What is / Full version
DMARC aggregate reporting
Aggregate reports summarize authentication results over time and are sent to rua URIs.
Short answerAll topics in What is
Report cadence
Receivers choose how often to send aggregates within the constraints of RFC 7489. Large receivers may send daily files per domain. Small volumes may arrive less often.
Each file lists sources by IP and includes counts of messages that passed or failed SPF, DKIM, and DMARC independently, because misalignment can fail DMARC while SPF alone passes.
External destination verification
When a report should go to a mailbox outside the organizational domain, RFC 7489 defines a DNS verification record at the destination domain so receivers know the owner consented.
Schema
RFC 7489 publishes an XML schema for aggregate reports. Processors group rows by source IP and reported disposition, not by individual Message-IDs.
The policy section of a report can include PolicyOverride when a receiver deviated from the published p= mode. That field is how operators learn when a receiver applied its own judgment.
Using reports
Operators read aggregates to find sources that send as the domain without alignment, then add SPF includes or DKIM signing for those sources before tightening policy from none toward quarantine or reject.
Forensic ruf streams are optional and expose message-level detail. They are governed by different privacy expectations than high-volume aggregates.
Report files use a published XML schema in RFC 7489. Each row's source IP is not itself proof of abuse; it is the address the reporter saw when the message arrived.