Report metadata

  • The reporting organisation and contact details.
  • A report identifier.
  • The start and end of the reporting period.
  • Any report-level errors.

Published policy

  • The domain evaluated by the reporter.
  • The p and sp policies observed.
  • SPF and DKIM alignment modes.
  • The percentage or other applicable policy settings.

Records

Each record normally gives a source IP, message count, policy-evaluation result and authentication details. One report can contain many records and many reports can cover the same domain from different receivers.

source_ip: 192.0.2.10
count: 2841
dkim: pass
spf: pass
disposition: none

Important limitations

  • Reporters vary in coverage and timing.
  • A source IP alone may not identify a commercial service.
  • Counts are aggregated and should not be treated as message logs.
  • Aggregate data can still expose sending infrastructure and relationships.
Further readingDMARC aggregate reporting — RFC 9990