Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

What is

DMARC aggregate reports

DMARC aggregate reports are XML files sent to the addresses in the policy's rua tag. RFC 7489 defines the format. They summarize which IP addresses sent mail claiming the domain, and whether SPF, DKIM, and DMARC passed or failed.

The rua tag holds a comma-separated list of URIs, commonly mailto:​ destinations. Receivers that support aggregate reporting send periodic files covering a time window, not one file per message.

What the XML contains

RFC 7489's schema groups rows by source IP, message count, and disposition. Each row can list SPF and DKIM auth results separately from the DMARC result, because alignment is evaluated after those mechanisms run.

Forensic reports, when published with an ruf tag, are a different stream with a different privacy profile. Aggregate reports are the high-volume telemetry most domains start with when they add p=none.

Starting with p=none

Domains often publish p=none while collecting aggregates to learn which senders need SPF or DKIM fixes before moving to quarantine or reject.

The ruf tag is for optional forensic reports. It is not required for aggregate reporting and carries different data than rua files.

Receivers that support aggregate reporting gzip the XML and mail it to each listed mailbox. Parsing is left to the domain owner or a report processor.