Free tool

Where do your DMARC reports go?

Type a domain and read the answer straight off its DNS: whether its DMARC record asks for reports at all, and which addresses receive them. Aggregate and failure reports are shown apart, because they are not the same thing — and the tool never decides for you whether the addresses are the right ones.

The domain your email comes from — the part after the @. We read its public DNS and nothing else; a whole address or a pasted URL works too.

Reading the result

What the answer tells you — and what it cannot

rua and ruf are not one thing

The aggregate tag (rua=) asks for the daily summary every provider already compiles about your domain — the data all DMARC monitoring is built on. The failure tag (ruf=) asks for a copy of individual messages that failed authentication, which most providers never send at all. A record can set one, both or neither, so they are shown as the two separate questions they are.

We do not judge the addresses

The tool reads where reports are sent. It does not decide whether that is right, because it cannot: dmarc@some-vendor.example may be the platform you signed up for last month or a leftover from an agency you left three years ago, and both look the same in DNS. That is why the answer ends in a question rather than a verdict.

A record can be perfect and send nothing

Reports are only sent if the record carries a rua= tag. Everything else — the policy, the alignment settings, the syntax — can be exactly right while no provider has anywhere to put a summary. It is the most common reason a domain has DMARC and no data to show for it.

Not readable is not the same as not there

When the DNS does not answer, this page says so instead of reporting an absence. A failed lookup is a fact about the lookup, not about the domain — resolvers time out, networks blip, DNSSEC validation fails. Try again in a moment before concluding anything.

Nothing at the far end is checked

We read the DMARC record and stop there. Whether the mailbox accepts reports, whether it is full, whether the address still exists, whether anybody reads what lands in it — none of that is visible from DNS. A published address is a claim like every other line in a record.

This is a record, not your mail

One DNS lookup describes what a domain asks for, not what it sends. How much mail leaves in your name, who else sends as you, and whether any of it authenticates lives in the reports themselves — which is exactly what starts arriving once the address is right.

Questions

About this tool

Do I need an account?

No. No sign-up, no email address to leave, no limit per person — just a cap of a few lookups a minute, so the tool stays open to everyone.

Do you store the domain I type?

No. It goes from your browser to the lookup API, which reads public DNS and answers without writing the domain to a database, a file or a log. The page keeps nothing either: no history, no browser storage, nothing handed to analytics.

It says my record has no rua= tag. What do I add?

A rua=mailto: entry pointing at a mailbox that can take the volume — providers send roughly one summary per domain per day each, so a domain with a wide reach can mean dozens of messages daily, most of them XML attachments. Reports usually start arriving within 24 to 48 hours of publishing the tag.

Should I set ruf= as well?

Usually there is little to gain. Failure reports can carry recipient addresses and subject lines, which is precisely why most providers stopped sending them, and the few that do send very little. The picture you are looking for is in the aggregate reports.

I recognise one address but not the other. Is that bad?

It is worth finding out, not worth panicking about. Domains commonly send reports to two places on purpose — a monitoring platform and an internal mailbox — and old entries survive supplier changes for years. Find out who owns the address before removing it: deleting an entry stops data arriving somewhere that may still be in use.

Can somebody else read my DMARC reports?

Anybody can read the addresses in your record: it is public DNS, which is how this tool works at all. What they cannot do is receive the reports — providers send those only to the addresses the record names, and only after checking that a mailbox on another domain has agreed to accept them.

The address is right. Now what arrives there?

Point rua= at Sentinely and the daily summaries stop being XML attachments: every source sending in your name, named, with what authenticated and what did not — for the whole domain, every day.