1. Add a domain
Create an account, add a domain you control and receive a unique reporting address. The dashboard shows the exact records needed for that domain.
- A unique RUA address keeps incoming reports attributable to the correct account and domain.
- DMARC Analyst never asks for your DNS login.
- Domain ownership and external-reporting authorisation are checked before reports are associated with the account.
2. Publish the reporting connection
Add the supplied mailto address to the rua tag in your existing DMARC record. Because the destination is outside your own domain, participating receivers also look for a TXT record that authorises DMARC Analyst to accept the reports.
v=DMARC1; p=none; rua=mailto:your-id@rua.dmarcanalyst.comKeep any existing RUA destinations by separating addresses with commas. Do not publish the example address above; use the unique value shown in your account.
3. Reports arrive and are bounded
Mailbox providers usually send compressed XML reports covering a reporting period. The receiver applies message, compressed archive, expanded data and file-count limits before any report is processed.
- Unsupported attachments and malformed archives are rejected.
- The original accepted report is preserved for traceability.
- Processing can be separated from reception as volume grows.
4. Results become actions
The application groups observations by domain, source and authentication result. Instead of reading XML, you can see legitimate platforms, unknown sources, alignment failures and changes over time.
- Identify every service sending with your visible From domain.
- See whether SPF, DKIM or both produced DMARC alignment.
- Review a new source before moving towards quarantine or reject.
Disconnecting
Removing a domain from the service disables its unique reporting address and withdraws managed external authorisation. You should also remove the address from your DMARC record. Compliant receivers will stop sending to an external destination once authorisation is absent.