1. Confirm the report period and policy
Check which domain and date range the reporter evaluated. If the published policy shown is unexpected, confirm DNS history and propagation before analysing individual rows.
2. Group by source and volume
Large, stable sources are usually easier to identify. Low-volume sources can still be important: password reset systems, finance platforms and seasonal campaigns may send rarely.
- Known platform and expected volume.
- Known platform but unexpected authentication result.
- Unknown source needing ownership investigation.
- Likely forwarding or indirect mail flow.
3. Follow the aligned identifier
A row can show SPF pass and still fail DMARC because the authenticated Mail From domain is unrelated. The same is true of a passing DKIM signature from a provider-owned domain.
Ask which passing domain aligned with the visible From domain—not simply whether the words SPF pass or DKIM pass appear.
4. Compare multiple periods
One day is evidence, not a complete inventory. Look for recurring sources, first-seen events and changes after configuration work before tightening policy.