← Back to Blog

Lappu AI Journal

How to Read and Act on DMARC Reports

DMARC reports are one of the most powerful tools for protecting your domain from spoofing and abuse - yet many businesses overlook them. In this post, we walk you through how to interpret DMARC aggregate reports and understand what they reveal about your domain’s email-sending behavior. You'll learn how to spot alignment issues with SPF and DKIM, detect potential spoofing attempts, and decide how to act based on the data. We use real anonymized XML snippets and visual examples to break down common scenarios: when everything is aligned, when only DKIM passes, and when neither SPF nor DKIM aligns. You’ll also learn why alignment is critical, how to identify third-party senders misconfigured on your behalf, and what actions to take before tightening your DMARC policy. Whether you’re just starting out with DMARC or looking to make data-driven decisions, this guide gives you the confidence to protect your domain’s reputation.

Vivek Uppal • August 3, 2025

How to Read and Act on DMARC ReportsSo you've set up your DMARC policy, published the DNS record, and are finally getting DMARC reports in your inbox or dashboard. Great!Now what?In this post, we’ll show you how to read and act on DMARC aggregate reports, using real anonymized examples, XML snippets, diagrams, and a practical framework to help you protect your domain from abuse.---------------------------------------------------------------## What Are DMARC Reports?DMARC reports are machine-readable XML files that email receivers (like Google, Microsoft, Yahoo) send you to show:- Who is sending emails from your domain- Whether those emails passed or failed SPF and DKIM- What action was taken (delivered, quarantined, rejected)- How often those events occurredThere are two types of reports:- Aggregate reports (sent daily, show summary data — what we focus on here)- Forensic reports (optional, contain message-level detail, often disabled for privacy)### Why Aggregate Reports MatterAggregate reports offer a high-level daily snapshot of how your domain is being used — or abused — across the internet. Without them, you’re flying blind. These reports help you:- Detect unauthorized senders or spoofing attempts- Monitor compliance across third-party services- Guide your decision to tighten DMARC policy over timeThey are essential for making data-driven email security decisions.---------------------------------------------------------------## What is SPF, DKIM AlignmentBefore we dive into the technical details, it’s important to understand What is SPF, DKIM alignment and why this is so critical in DMARC.SPF and DKIM are the building blocks of DMARC. A successful DMARC policy evalaution requires that both SPF and DKIM checks pass and both the checks are aligned, i.e. both these checks pass for the same domain. Alignment makes sure that the domain used for authentication is truly yours. Without alignment, SPF and DKIM could technically pass while your customers still receive spoofed emails.Alignment ensures that the domain that passes SPF or DKIM matches the domain in the 'From' header of the email. This prevents attackers from using valid SPF or DKIM records for domains attackers control to send email that appears to be from your domain.---------------------------------------------------------------## Case 1: Both SPF and DKIM AlignedThese are clean, legitimate sends. Usually from your business’s main mail provider (e.g., Google Workspace, Microsoft Outlook, Mailchimp).| Source IP | From Domain | SPF Aligned | DKIM Aligned | Result | Count |

|----------------|------------------|-------------|---------------|------------|-------|

| 203.0.113.12 | yourdomain.com | ✅ Yes | ✅ Yes | Pass | 120 |** DMARC XML Snippet:**DMARC XML Example---------------------------------------------------------------## Case 2: DKIM Passes, SPF Fails (Partial Alignment)Common when using ESPs like SendGrid that sign DKIM properly but don’t align SPF.| Source IP | From Domain | SPF Aligned | DKIM Aligned | Result | Count | |----------------|------------------|-------------|---------------|------------|-------|

| 198.51.100.99 | yourdomain.com | ❌ No | ✅ Yes | Pass | 30 |** DMARC XML Snippet:DMARC XML Example---------------------------------------------------------------## Case 3: Neither SPF nor DKIM Aligned (Likely Spoofing)Almost certainly spoofing or misconfiguration. These emails should be rejected.| Source IP | From Domain | SPF Aligned | DKIM Aligned | Result | Count | |----------------|------------------|-------------|---------------|------------|-------| | 45.67.89.120 | yourdomain.com | ❌ No | ❌ No | Fail | 5 | DMARC XML Snippet:**DMARC XML Example---------------------------------------------------------------LappuAI Email Security Platform provides the tools to analyze reports in great detail and remediate the issues.DMARC Report AnalysisWe’ve covered the most common DMARC cases and how to act on them. Of course a lot more variations are possible and there are a number of complex cases.Get in touch to analyze your reports. We are happy to assist.