The Premium DNS Plus report reader helps you inspect a DMARC aggregate report received from an email provider. It summarises the sending servers and authentication results in that file. It does not scan your inbox or determine whether an individual email message is a scam.
IN THIS ARTICLE
01 Obtain a report
Your domain must have an appropriate DMARC TXT record if you want participating mail providers to send aggregate reports. Reports go to the reporting address configured in that record. Access the reporting mailbox and save the actual XML report or its supported compressed attachment. Reporting frequency and participation are controlled by the sending provider.
02 Open the file
- Select the domain in DNS Manager and open Health.
- Find Email reports. This section appears only when your active plan and the provider settings include it.
- Select Open a report file.
- Choose the XML, gzip or ZIP report offered by your mail provider. The reader accepts a bounded upload, currently up to 1.5 MB.
- Check the report's domain, reporting organisation and date range before interpreting the totals.
03 Interpret the results
The view lists sending IP addresses, message counts and SPF/DKIM evaluation outcomes. A passing result indicates that the report recorded the relevant aligned authentication outcome. It does not prove the message content was wanted. A failing result may indicate spoofing, a legitimate sending system that has not been configured correctly, or forwarding-related changes that need investigation.
Compare the sending sources with the services your organisation actually uses. Check website contact forms, billing systems, newsletters and staff mail platforms. Correct authorised senders before tightening a DMARC policy that could reject their mail. Do not authorise an unfamiliar sender in SPF solely because it appears in a report.
Which DMARC report files can I upload, and is the report stored?
The reader processes the uploaded report without storing it as an ongoing report collection. Keep your original file if you need historical comparisons. Large or malformed files can be rejected, and a report for another domain is flagged. Several files from different reporting providers may cover overlapping periods; their totals are not automatically a deduplicated count of all messages sent.
If the upload fails, confirm it is a DMARC aggregate report, not a delivery-status message or a screenshot. Extract a supported XML report locally when appropriate, then try again within the displayed size limit.