Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

What is / Full version

DMARC aggregate reporting

Aggregate reports summarize authentication results over time and are sent to rua URIs.

Short answerAll topics in What is

Report cadence

Receivers choose how often to send aggregates within the constraints of RFC 7489. Large receivers may send daily files per domain. Small volumes may arrive less often.

Each file lists sources by IP and includes counts of messages that passed or failed SPF, DKIM, and DMARC independently, because misalignment can fail DMARC while SPF alone passes.

External destination verification

When a report should go to a mailbox outside the organizational domain, RFC 7489 defines a DNS verification record at the destination domain so receivers know the owner consented.

Schema

RFC 7489 publishes an XML schema for aggregate reports. Processors group rows by source IP and reported disposition, not by individual Message-IDs.

The policy section of a report can include PolicyOverride when a receiver deviated from the published p= mode. That field is how operators learn when a receiver applied its own judgment.

Using reports

Operators read aggregates to find sources that send as the domain without alignment, then add SPF includes or DKIM signing for those sources before tightening policy from none toward quarantine or reject.

Forensic ruf streams are optional and expose message-level detail. They are governed by different privacy expectations than high-volume aggregates.

Report files use a published XML schema in RFC 7489. Each row's source IP is not itself proof of abuse; it is the address the reporter saw when the message arrived.