Report metadata
- The reporting organisation and contact details.
- A report identifier.
- The start and end of the reporting period.
- Any report-level errors.
Published policy
- The domain evaluated by the reporter.
- The p and sp policies observed.
- SPF and DKIM alignment modes.
- The percentage or other applicable policy settings.
Records
Each record normally gives a source IP, message count, policy-evaluation result and authentication details. One report can contain many records and many reports can cover the same domain from different receivers.
source_ip: 192.0.2.10
count: 2841
dkim: pass
spf: pass
disposition: noneImportant limitations
- Reporters vary in coverage and timing.
- A source IP alone may not identify a commercial service.
- Counts are aggregated and should not be treated as message logs.
- Aggregate data can still expose sending infrastructure and relationships.
Further readingDMARC aggregate reporting — RFC 9990