Back to the knowledge base
Authenticatiedmarcrapporten

Reading DMARC reports in 2Mail

A DMARC record asks receiving mail servers to report which mail arrived on behalf of your domain and whether it passed SPF and DKIM. Those reports are raw XML files that nobody enjoys reading. The 2Mail dashboard collects them per sending domain and turns them into an overview you understand at a glance.

Step 1: the DMARC record with a report address

Open your sending domain in the dashboard and let 2Mail propose the DMARC record. That record contains a 2Mail report address, so the reports arrive with us and not in your own mailbox. Put the record as a TXT record on _dmarc under your domain, in the DNS management of your registrar or hosting panel. Start with the policy none: then only reporting happens and nothing is blocked yet.

Step 2: wait for the first reports

Recipients usually send reports once a day. Allow two to three days before you have a usable picture, and a few weeks if you send little.

Step 3: read the overview

For your sending domain the dashboard shows per source — that is, per sending server or service — how many messages were seen and what share of them passed SPF and DKIM. Look at three things:

  • Known sources that pass: 2Mail itself, your office mail, your CRM. That is the normal picture.
  • Known sources that fail: a service that does send on your behalf but is not in your SPF record or does not sign with DKIM. Fix it, or that mail will soon land in the spam folder.
  • Unknown sources: servers you do not recognise. A small volume is often forwarded mail; a large volume that fails everywhere is someone abusing your domain.

Step 4: tighten the policy

Once all your own sources pass for several weeks in a row, set the policy to quarantine and later to reject. From then on recipients may put mail that fails the checks in the spam folder or refuse it. Change the value in your DNS; the dashboard keeps showing the reports and reveals whether the number of rejected messages rises.

What you do not have to do

Open the XML files yourself. If you do receive a report directly, for example because an old record still points at your own mailbox, you can replace the report address in the record with the 2Mail one.

Where it goes wrong

  • No reports after a week — the record is on the wrong domain or the report address was copied wrongly.
  • Everything fails, including 2Mail — the sender domain in your messages differs from the domain on which you set up SPF and DKIM.
  • Forwarded mail fails SPF — that is normal; DKIM stays valid and DMARC passes.

The full explanation of the three records is on SPF, DKIM and DMARC; what it means for your delivery on email deliverability.

Still stuck?

Send us your domain name via contact. We look at the reports with you and tell you which source still needs fixing.

#read dmarc reports#set up dmarc record#dmarc report xml#dmarc quarantine reject#dmarc dashboard
Still stuck?

Does it behave differently than described above, or are you stuck anyway? Get in touch with your domain name or customer number at hand and we will take a look with you.

Contact support
Call us
Send an email