Reach p=reject without rejecting mail people wanted
The reports tell you which sources still fail alignment and how much they send. You move the policy when that list is empty, not when it feels like enough time has passed

Aggregate reports, read for you
The XML every large receiver sends back becomes a table of sources, volumes and pass rates, with a year of history behind it
- Sources named, not just addresses
- SPF and DKIM results per source
- Volume behind every result
- Up to 365 days to look back through

Forensic reports
The individual messages that failed, as the receiver sent them, with headers and subject as received
- Headers and subject as received
- Authentication result per message
- Who sent the report, verified
- Personal data, so treat the view as such

The record itself
Your published policy is parsed the way RFC 9989 defines it, including the tags that replaced the ones people still copy from old guides
- p, sp and np read separately
- Alignment mode for SPF and DKIM
- t=y recognised as testing
- rua and ruf addresses parsed and shown

What the DMARC work actually gives you
Enforcement is a decision about other people mail. These are the things you need to make it without guessing
Every source, with its volume
Including the ones you forgot
Each sending address in the reports is attributed to the service behind it and shown with how much it sends and how much of that passes. The invoicing tool nobody remembered is usually in this list
What a stricter policy would have done
Before you publish it
The reports already contain what each receiver decided. You can see how much real mail would have been quarantined or rejected under a stricter policy, which turns the move to enforcement into arithmetic rather than nerve
Who really sent the report
Not who the report says it is
A report names its own author in a field anybody can write. We record the domain that actually authenticated when it was delivered, and flag a reporter this domain has never seen before, because a forged report is a cheap way to make your numbers look wrong
A policy read as receivers read it
RFC 9989, not the 2015 guide
The tags changed. np applies to subdomains that do not exist, t=y marks the policy as testing and stops it being enforced, and pct no longer does what old advice says. Your record is parsed the way it is now interpreted
Reports that reach you at all
The rua address is checked
A reporting address on a domain with no MX silently receives nothing, and you conclude that nobody is spoofing you. The addresses in your rua and ruf tags are parsed out and shown, including the external-destination form, so you can check the one thing an empty report view will not tell you
Taking the data with you
CSV and PDF from the browser
Any report view exports to CSV for a spreadsheet or PDF for somebody who asked for evidence. The export covers the whole range you are looking at, not only the rows currently on screen
What each policy value is worth, and what quietly lowers it
Two tags change the policy receivers actually apply, and one of them is widely believed to do something it no longer does
| Published | Enforcement score | What receivers do with it |
|---|---|---|
| p=reject | 100 | Failing mail is refused at the door, so nothing lands in a folder for someone to find later |
| p=quarantine | 70 | Failing mail is delivered to spam. Better than nothing and still delivered |
| p=none | 10 | Nothing changes. Reports arrive and no message is treated differently |
| t=y alongside any of them | One rank lower | Test mode. A domain publishing reject with t=y is scored as quarantine, because that is what receivers apply |
pct is parsed and shown but no longer scored. RFC 9989 marks it historic, so a record reading reject with pct=50 has reject applied to everything
Three steps to enforcement
The order matters. Publishing a strict policy before you can read the reports is how legitimate mail gets rejected
Publish p=none with a reporting address
Nothing is rejected and receivers start sending you reports. Point rua at an address on a domain that actually receives mail
Wait for the sources to appear
Within a couple of weeks the reports list everything sending as you. Fix alignment for the ones you recognise, and look hard at the ones you do not
Move the policy when the list is clean
Quarantine first, then reject. You will see in the reports what each step actually cost, and you can go back if it cost too much
Questions about DMARC
What the reports contain, how long to stay at p=none, and what changed in the standard in 2026
Mailbox providers usually send aggregate reports once every 24 hours. Your dashboard will show the first normalized data within 24 to 48 hours after the record goes live.
Yes. Aggregate reports show overall patterns, while forensic reports contain individual messages that failed authentication, as the receiver sent them. Those messages carry headers, subject lines and envelope addresses belonging to real people, and they are stored as received, so treat the forensic view as personal data and keep access to it narrow.
Starting with p=none lets you collect data without impacting mail delivery. This approach helps you identify legitimate senders like SaaS platforms that are not yet fully aligned, giving you time to fix configuration issues before tightening enforcement.
We do not run forwarding detection of our own, so no record is tagged as a mailing list or an alias. What forwarding leaves behind is still readable, because a forwarded message almost always fails SPF, the relaying IP not being in your record, while your DKIM signature usually survives the trip. The failures view separates records on exactly that line, so one where a single check still passes reads differently from one where both failed, and the ARC panel shows which intermediaries handled your mail.
No, that file is not downloadable. It is stored for 90 days and then deleted, and nothing in the product hands it back to you in the meantime. What you can take out is the parsed report as raw JSON, which every report opens and copies, plus CSV or PDF of any report view, on every plan including the free one. The CSV covers the whole range you are looking at rather than the page on screen. Nothing is delivered by email and there is no export endpoint.
See who is sending as you
Publish a reporting address today and the first reports usually arrive within a day. One domain is free and nothing asks for a card