Private file analysis · current RFC 9990
Free DMARC aggregate report reader.
Turn receiver XML into clear source, alignment and disposition evidence. Read several reporting periods, compare sending sources and export the rows you need.
Read a DMARC reportAdd receiver reports
Analyse XML without sending it anywhere.
Select up to 20 reports. Exact duplicate report IDs from the same reporting organisation are counted once.
Choose XML or GZIP-compressed XML files to begin.
Stays in this browser. File contents are not submitted, logged, added to analytics or stored by ACA Tech. Closing or refreshing clears the analysis.
Aggregate evidence
What receivers reported.
Not supplied · policy domain(s): Not supplied
Start with recognition, not blocking. Match high-volume sources against your approved sender inventory. Forwarding, mailing lists and provider configuration can all create failures; aggregate XML alone cannot identify intent.
Authentication paths
How messages achieved—or missed—alignment.
These are DMARC-aligned DKIM and SPF results reported by receivers, not every underlying authentication attempt.
Receiver actions
Reported disposition.
The action recorded in a report can reflect published policy, test mode, an override or receiver discretion. It is not a delivery or inbox-placement report.
Highest observed volume
Source IP evidence.
An address is an observation point—not automatically a vendor, employee, attacker or trusted sender.
Report cautions
What needs contextual review.
Provenance
Reports included.
Keep report organisation, ID, period and published policy attached to the evidence you review.
Normalised rows
Search the receiver observations.
Showing 0 matching rows.
| Source IP | Messages | Header From | DMARC | Aligned paths | Disposition | Reporter |
|---|
No rows match these filters.Clear the search or choose all outcomes.
Use evidence safely
A failure is a question—not a verdict.
Recognise
Compare the source and From domain with services your organisation actually authorises.
Verify
Use representative message headers and provider settings to confirm authentication and alignment.
Classify
Separate legitimate misconfiguration, forwarding and mailing lists from genuinely unexplained traffic.
Change carefully
Adjust a sender or DMARC policy only with a monitored window, accountable owner and rollback path.
Current report format
XML and GZIP, as RFC 9990 defines them.
The current aggregate-report specification uses a feedback XML document and recommends GZIP compression. This reader accepts .xml, .xml.gz and .gz; it does not silently treat ZIP as the standard format.
Bounded file handling
Up to 20 files, 10 MB each, 25 MB expanded per file, 40 MB combined and 50,000 report rows.
Defensive XML parsing
Document types and entities are rejected. Familiar fields are parsed locally; this is not full XSD conformance validation.
Safe export
The local CSV includes every parsed row and neutralises leading spreadsheet-formula characters.
Aggregate report questions
Understand what the XML can—and cannot—say.
Where are DMARC report files analysed?
Reading, GZIP expansion, aggregation, filtering and CSV generation all happen in this browser. Refreshing the page clears the current analysis.
Does a failed source IP mean malicious email?
No. It may be an unauthorised sender, a legitimate service configured incorrectly, forwarding, a mailing list or abuse. Confirm ownership and message evidence before classifying it.
Why does the reader reject ZIP files?
RFC 9990 defines plain XML or GZIP-compressed XML aggregate attachments. If someone supplied a ZIP, extract it locally only when you trust its source, then select the contained XML.
Can I add several reports together?
Yes. Totals are summed across unique reporting-organisation and report-ID pairs. Check the displayed periods and policy configurations before comparing or combining conclusions.
Does a strong pass rate mean DMARC enforcement is safe?
Not by itself. Reports may not represent every receiver, day, sender or indirect path. Use a maintained sender inventory, representative periods, message-level verification, change approval and rollback planning.