WoluTools

DMARC Aggregate Report Analyzer

DMARC Aggregate Report Analyzer Online: see who is sending mail as your domain.

Upload the XML reports that mailbox providers send you. You get one list of every server that sent mail as your domain, with SPF and DKIM results, and the unauthenticated ones at the top.

XML, XML.GZ or ZIP. Free: 3 jobs a day, no account needed, files deleted after processing.Limits & Pro

EXAMPLE RESULTFictional sample data

Top sending sourcesexample.com · 42 reports · 148,220 messages

Top three sending sources in the fictional sample for example.com
Source IPMessagesSPFDKIMAligned
203.0.113.1096,400passpassyes
192.0.2.4526,770failpassyes
198.51.100.24Unauthenticated12,480failfailno

6 more sources to review · 12,570 messages

One server sent 12,480 messages that pass neither SPF nor DKIMA source counts as aligned when SPF or DKIM passes for your domain. 83.1% of the sample's mail is aligned; 7 sources need work.

DMARC reports: a 15-second video

A short animated example of alignment and sending sources. German text; no sound is needed.

Silent · 15 seconds
Download video (16:9)Download vertical video (9:16)

THREE STEPS

From report attachments to a worklist.

  1. 01
    Add your reports

    Upload the XML, .xml.gz or ZIP attachments from your DMARC mailbox. Compressed files are unpacked for you.

  2. 02
    Read the worklist

    Each sending IP is listed with its message count and SPF and DKIM results. Unauthenticated sources come first.

  3. 03
    Download

    Take the HTML report, or the data as XLSX, CSV or JSON.

Prepared example

What the report finds in 42 sample reports

The example uses fictional reports for example.com and is processed the same way as your own files.

✓
Nothing is uploadedPublic demo only
Messages
148,220
Aligned
83.1%
Sources to review
7
Unique reports
42
  • Fix firstUnauthenticated high-volume source198.51.100.24 sent 12,480 messages. Neither SPF nor DKIM aligned with example.com.
  • NextPolicy still at noneEvery supplied report shows p=none, so receivers are not asked to act on failing mail.
  • NoteDuplicates counted onceReports with the same report ID are dropped, so a file sent twice does not inflate the counts.

What you download

  • HTML report to read in the browser or pass on
  • XLSX workbook for filtering and sorting in Excel
  • CSV and JSON for your own scripts or tickets
  • Checksum list of every file, so you can tell if one was changed

How it works

What happens to your reports

  • Before the job starts, you see the file list and what the download will contain. Nothing runs until you confirm.
  • Each job runs on its own, in an isolated environment without network access.
  • No DNS lookups and no mailbox access. The published policy is read from the reports themselves.
  • Your uploaded files are deleted after processing, and the result is stored encrypted.

What it cannot tell you

Aggregate reports only show what receivers saw during the period they cover. A sender that was quiet in that window does not appear, so a clean result does not prove the domain is fully protected.

Limits & Pro

Limits, file handling and plans

Every job

  • Up to 64 report files and 64 MB in total
  • ZIP archives: up to 2,000 files inside, 128 MB once unpacked
  • Formats: XML, XML.GZ and ZIP

File handling

  • Uploaded files are deleted after processing
  • Unfinished drafts are removed after 2 hours
  • The encrypted result is kept for 24 hours

Free

  • 3 jobs a day, no account needed
  • Up to 3 files per job, each up to 10 MB
  • Failed jobs are never counted; the counter resets at midnight UTC

Pro

  • Up to 200 jobs a day
  • Larger files and batches
  • €12.99 a month or €89.99 a year, cancel anytime

Clear answers

DMARC Aggregate Report Analyzer FAQ

Which report files does the analyzer accept?

Aggregate RUA reports as XML, gzipped XML or ZIP archives. These are the compressed attachments that mailbox providers send out daily. You can add many reports to one job; the exact limits are listed under Limits.

How are duplicate reports handled?

Reports are keyed by their report ID, so uploading the same aggregate twice does not double the message counts. The prepared example shows 42 unique reports once duplicates were dropped.

What does a failing sending source look like?

A sending address with real volume where neither SPF nor DKIM aligns with your domain. Those sources head the worklist, with the address, the message count and the mechanism that failed.

Does the tool query DNS or read my mailbox?

No. It works only from the XML you upload. The published policy is read out of the reports themselves rather than looked up, so no DNS or mailbox access is needed.

Does a clean report mean the domain is protected?

No. Aggregate data only shows what receivers observed during the period the reports cover, so a source that stayed quiet in that window simply does not appear.

Available now

See who is sending mail as your domain.

Upload the reports from your DMARC mailbox and get one list of every sending source, unauthenticated ones first.