01 / GETTING STARTED

How to use Dmarcread in three steps.

Dmarcread is a browser-only tool. There is nothing to install, no account to create, and nothing to configure. You feed it DMARC aggregate report files and it shows you what the reports contain.

  1. Get your DMARC aggregate reports. If your domain publishes a DMARC policy with a rua address, mailbox providers send daily aggregate XML reports to that address. You receive them as email attachments — typically .xml.gz or .zip files. If you do not yet receive reports, see the FAQ below on setting up DMARC reporting.
  2. Open the app and drop in your files. Go to the Dmarcread app and drag one or more report files onto the drop zone. You can also click to select files. Dmarcread accepts .xml, .xml.gz, and .zip files as received from mailbox providers.
  3. Read the results. The page groups every sending source into three lists: sources that passed SPF and DKIM alignment, sources that probably belong to you but failed alignment, and unidentified sources. Each source gets a one-sentence verdict. Download the full results as a CSV file if you need them offline.

02 / FREQUENTLY ASKED QUESTIONS

Questions from people who read DMARC reports.

How do I get DMARC aggregate reports for my domain in the first place?

You need to publish a DMARC DNS record that includes an rua (reporting URI for aggregate reports) address. For example: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. Once that record is published, mailbox providers that honour DMARC will send daily aggregate reports to the address you specified. Dmarcread does not sign you up to receive reports or host a receiving address — it reads files you already have.

Why does a source appear in "probably yours" or "unidentified"?

A source is placed in "probably yours" when the report shows it failed SPF alignment or DKIM alignment, but its reported hostname matches a service Dmarcread recognises — Mailchimp, Salesforce, Zendesk, SendGrid, and several others. "Unidentified" means the hostname did not match any known service. In both cases, a verdict tells you which check failed (SPF, DKIM, or alignment). It is your decision whether the source is legitimate and needs authentication fixes, or is spoofing.

Can Dmarcread tell me if someone is spoofing my domain?

No tool can tell you that from a DMARC aggregate report alone. Dmarcread shows you which sources failed authentication checks and sorts them by recognisability. A source in "unidentified" could be a spoofing attempt — or it could be a contractor's newsletter tool, a forgotten dev server, or a service you use that was never configured to sign with DKIM. That judgment requires context you have and Dmarcread does not.

Does Dmarcread check DNS records or blocklists?

No. Dmarcread reads only what the report file contains. It does not query your SPF, DKIM, or DMARC records. It does not check any blocklist or reputation database. The tool cannot tell you whether your DNS records are correctly configured — that is outside the scope of a DMARC aggregate report.

I dropped in a file and the page says "no results" or nothing appeared.

The most common cause is file format. Dmarcread accepts .xml, .xml.gz, and .zip files exactly as received from your mailbox provider. If you extracted the XML from inside a ZIP before uploading, try uploading the original ZIP instead — Dmarcread decompresses archives automatically. Make sure the file is a valid DMARC aggregate report with a <feedback> root element. Some providers also send failure reports (forensic/FRF reports) which have a different XML structure — Dmarcread does not parse those.

How do I save or export the results?

Once results are displayed, click the Download CSV button above the results panel. The CSV file is generated entirely in your browser — no data is sent to any server. Results are not saved between visits; if you close the tab or refresh the page, everything is gone. Export to CSV before navigating away if you need to keep the data.

03 / KNOWN LIMITATIONS

What Dmarcread does not do — and what is not built yet.

Dmarcread is a browser-based DMARC aggregate report parser with a deliberately constrained scope. The following are not bugs — they are architectural boundaries or planned items that do not yet exist.

04 / CONTACT US

How to reach a human.

If you have a question that is not answered here, or you need to report an issue with the tool, you can reach the team by email.

Email

dmarcread-p3@agen2ic.ai

The dmarcread-p3 local part identifies which product your message is about so it reaches the right person. agen2ic.ai accepts mail at any local part. Expect a reply within one to two business days.

Before you email: Please check the FAQ above and the home page — your question may already be answered. If you are reporting a parsing issue, including the report file (or a sanitised excerpt) in your email helps us diagnose it faster.

There is no phone number, chat, or social media support route for this product. Email is the only channel.