Reading a DMARC report
DMARC reports arrive as XML and are unreadable by eye. But they answer a valuable question: who is sending mail in your name?
What they contain
Per sending server: how many messages, and whether SPF and DKIM passed. That is all, and it is enough.
What you look for
Servers you do not recognise. These are either legitimate systems you had forgotten — the invoicing tool, a website form, a supplier — or somebody abusing your domain.
The most common discovery
Almost everybody finds at least one legitimate system missing from their SPF. That is exactly what observation mode is meant to reveal before you tighten the policy.
Use a reader
Raw XML is not workable by hand. A service that aggregates them turns weeks of files into a clear picture.
Then tighten
When all legitimate sending passes, move from observation to quarantine, then to reject. Not before.