DMARC Report Reader

Paste or upload aggregate (rua) XML / ZIP / GZ reports or forensic (ruf) failure reports — decoded into plain tables, entirely in your browser.

How it works

Reports stay on your device. Nothing is uploaded or stored.

Frequently asked questions

What's the difference between rua and ruf reports?

rua (aggregate) reports are XML summaries: who sent mail as your domain, in what volume, and whether SPF/DKIM/DMARC passed — usually delivered as .zip or .gz attachments. ruf (forensic) reports are individual failure samples with the offending message attached. This reader decodes both.

Where do I get these reports?

From your DMARC record's rua and ruf tags — mailbox providers send them to the addresses you publish there. If you haven't set them up, the DMARC generator can build the record.

Is my report data sent anywhere?

No. ZIP/GZ extraction, XML parsing and rendering all happen in your browser with JavaScript. The only network requests are optional reverse-DNS lookups of sender IPs, and only if you click that button.

It says "not a DMARC report" — what went wrong?

Either the file wasn't a rua XML (check it's the attachment from a DMARC report email, not the email itself), the ZIP used an unusual compression, or the XML is malformed. Paste the raw XML directly if the upload path fails.

What should I look for in the results?

Rows where DMARC fails with disposition none are your rollout risk — those senders will break when you move to quarantine/reject. Unknown IPs passing DMARC can indicate spoofing or a legitimate sender you forgot (mailing tools, CRMs).