Read your DMARC reports

Once DMARC is set up, mailbox providers email you daily reports listing everyone who sends mail as your domain. They arrive as unreadable compressed XML. Drop them here to see — in plain language — who's sending as you, what's passing, and whether it's safe to enforce.

Drop DMARC report files here

Accepts .xml, .xml.gz, and .zip — drop several at once.

No reports handy?

How to get your reports (and how this stays private)

  • Point DMARC at an inbox. The rua=mailto:you@yourdomain.com part of your DMARC record is where providers send daily reports. Don't have DMARC yet? Run the spoofing check — it generates the record for you.
  • Save the attachments. Each report email has a .gz or .zip attachment. Save them and drop them above — several at once is fine.
  • Nothing is uploaded. The files are decompressed and parsed entirely in your browser — they never leave your machine or reach this site. No account, no tracking.
  • This reads, it doesn't decide. It shows what your reports say and gives honest guidance. Before you move to "reject", confirm the failing sources really aren't yours.