← Back to docs

DMARC Monitoring

Monitor DMARC alignment across your sending domains

Overview

EuroMail ingests DMARC aggregate reports sent by receiving mail servers (Google, Yahoo, Microsoft, etc.), parses the XML, and presents the results in your dashboard. You can track alignment rates per domain, spot failing source IPs, and monitor trends over time -- all without leaving EuroMail.

How It Works

  1. You publish a DMARC DNS record with a rua tag pointing to EuroMail's reporting address.
  2. Receiving mail servers send aggregate reports as compressed XML attachments to that address (typically once per day).
  3. EuroMail's inbound SMTP server detects DMARC report emails by their subject line and attachment type.
  4. A worker decompresses and parses the XML (RFC 7489 Appendix C schema). Gzip, zip, and plain XML attachments are supported. Decompressed size is capped at 10 MB for security.
  5. Reports are stored in the database and linked to your account via domain ownership. Duplicate reports (same reporter + report ID) are skipped.
  6. The dashboard displays alignment rates, per-domain breakdowns, trends, and failing sources.

Setup

Add or update your DMARC DNS record to include EuroMail's reporting address in the rua tag:

_dmarc.yourdomain.com.  TXT  "v=DMARC1; p=reject; rua=mailto:[email protected]"

If you already have a rua tag with another address, append EuroMail's address with a comma:

_dmarc.yourdomain.com.  TXT  "v=DMARC1; p=reject; rua=mailto:[email protected],mailto:[email protected]"

EuroMail will automatically detect the rua tag during domain verification and suggest the correct record if it is missing.

If you are setting up DMARC for the first time, start with a monitoring-only policy and tighten it once your alignment rate is stable:

PhasePolicyPurpose
Monitorp=noneCollect reports without affecting delivery
Quarantinep=quarantineSend failures to spam
Rejectp=rejectBlock delivery of unauthenticated emails

Dashboard

The DMARC monitoring dashboard is available at DMARC Monitoring in the sidebar. Use the period selector to view data for the last 7, 30 (default), or 90 days.

Alignment Rate Card

The top-level card shows your overall alignment rate as a percentage, color-coded by threshold:

RateColorMeaning
95% or higherGreenHealthy alignment
80% -- 94%AmberSome sources are failing
Below 80%RedSignificant authentication issues

A message passes DMARC when at least one aligned mechanism passes -- aligned SPF or aligned DKIM (RFC 7489 §4.2). Both do not have to pass. DKIM-only alignment is normal and healthy: the bounce domain in the envelope rarely matches your From domain, so SPF often aligns for neither.

Summary Stats

Four cards show totals for the selected period:

  • Total Reports -- Number of aggregate reports received
  • Messages Analyzed -- Total message count across all reports
  • Passed -- Messages where at least one aligned mechanism passed
  • Failed -- Messages where SPF or DKIM (or both) failed

Per-Domain Alignment Table

A breakdown of alignment by domain, showing:

ColumnDescription
DomainThe sending domain from the report
MessagesTotal messages analyzed
SPF Pass %Percentage of messages that passed SPF
DKIM Pass %Percentage of messages that passed DKIM
Alignment %Percentage of messages that passed DMARC (aligned SPF or aligned DKIM)

Percentages are color-coded using the same green/amber/red thresholds. Sorted by message count descending.

Alignment Trend Chart

A dual-axis line chart showing daily data points:

  • Left axis: Alignment percentage (0-100%), orange line with fill
  • Right axis: Message count, gray dashed line

Use this to identify drops in alignment that correlate with changes in sending volume or infrastructure.

Top Failing Sources

A table of the top 20 source IPs that sent messages failing SPF or DKIM:

ColumnDescription
Source IPThe sending server's IP address
Header FromThe From domain in the message header
TotalTotal messages from this source
FailedMessages that failed alignment
Last SeenMost recent report containing this source

Sorted by failure count descending. A source appears only when both aligned mechanisms failed; passing on one alone is a DMARC pass and is not listed. If every source passes, this table is empty.

DMARC Reports List

The DMARC Reports page lists all received aggregate reports with:

  • Reporter organization (Google, Yahoo, Microsoft, etc.)
  • Domain
  • Report period (date range)
  • Policy badge (reject = green, quarantine = amber, none = gray)
  • Pass/fail counts

Click a report to view its full details, including the published policy, alignment modes (relaxed vs strict), and individual source records with per-record SPF and DKIM results.

Interpreting Results

SPF vs DKIM vs Full Alignment

  • SPF alignment -- The envelope sender domain matches the From header domain (or its subdomain, in relaxed mode). SPF alone can break when emails are forwarded.
  • DKIM alignment -- The DKIM signing domain matches the From header domain. DKIM survives forwarding because the signature travels with the message.
  • DMARC pass -- At least one aligned mechanism passes (RFC 7489 §4.2). This is what EuroMail measures for the alignment rate.

Common Failure Causes

SymptomLikely Cause
SPF failing from unknown IPsA third-party service is sending on your domain without being included in your SPF record
DKIM failingDKIM key rotation without updating DNS, or a forwarding server modifying the message body
Low alignment from a specific IPA misconfigured server or an unauthorized sender
Alignment drops after DNS changeSPF or DKIM records were accidentally modified or removed

Period Selection

All dashboard views support three time windows:

PeriodDescription
7 daysRecent activity, useful for spotting sudden changes
30 daysDefault view, balances recency with statistical significance
90 daysLong-term trends and seasonal patterns

Send your first email in about 90 seconds

The free tier includes 3,000 emails a month. All data stays in Finland | GDPR compliance without the paperwork.

Create free account See live delivery data