Back to Free Tools

    DMARC XML Report Preview

    Paste or upload a DMARC aggregate (RUA) XML report to view it in a readable format.

    Parse a DMARC XML report

    Max 256 KB decompressed. Gzipped reports are unzipped in your browser; we don't store the raw XML.

    What is a DMARC aggregate report?

    DMARC aggregate (RUA) reports are daily XML summaries from mailbox providers that show how mail claiming to be from your domain authenticated. Each report lists the source IPs, message counts, and SPF/DKIM alignment results so you can see which senders are passing and which are failing. They're the feedback loop you need to safely tighten DMARC policy.

    What this preview tool does

    • Parses the <feedback> envelope of a DMARC aggregate report
    • Extracts the reporter, date range, and published policy
    • Renders each <record> as a row with source IP, count, SPF, DKIM, and disposition
    • Reverse-DNS resolves source IPs so you can spot the sending platform
    • Calculates aligned vs failed message totals

    Field reference

    FieldXML pathMeaning
    Reporterreport_metadata/org_nameThe mailbox provider that produced the report.
    Date rangedate_range/begin..endUnix-epoch window the report covers.
    Policypolicy_publishedThe DMARC policy that was in effect at report time.
    Source IPrecord/row/source_ipThe IP that sent this batch of messages.
    Countrecord/row/countNumber of messages in this batch.
    SPF / DKIM resultpolicy_evaluated/spf,dkimWhether each mechanism aligned with the From: domain.
    Dispositionpolicy_evaluated/dispositionWhat the receiver actually did (none / quarantine / reject).

    How to fix failing rows

    • Look up the source IP — the reverse-DNS hostname usually tells you the platform (ESP, on-prem MTA, vendor)
    • For ESP rows: enable DKIM via the CNAME the vendor publishes so DKIM aligns with your domain
    • For on-prem rows: add the IP to your SPF record and confirm DKIM is signing
    • For rows you don't recognize: investigate — could be spoofing, or a legitimate sender you forgot about

    Frequently asked questions

    References

    Go beyond one-off checks

    Safer Sender continuously monitors your domain's DMARC, SPF and DKIM, classifies every sender, and guides you safely from p=none to p=reject.