01 / GETTING STARTED
How to use Dmarcread in three steps.
Dmarcread is a browser-only tool. There is nothing to install, no account to create, and nothing to configure. You feed it DMARC aggregate report files and it shows you what the reports contain.
- Get your DMARC aggregate reports. If your domain publishes a DMARC policy with a
ruaaddress, mailbox providers send daily aggregate XML reports to that address. You receive them as email attachments — typically.xml.gzor.zipfiles. If you do not yet receive reports, see the FAQ below on setting up DMARC reporting. - Open the app and drop in your files. Go to the Dmarcread app and drag one or more report files onto the drop zone. You can also click to select files. Dmarcread accepts
.xml,.xml.gz, and.zipfiles as received from mailbox providers. - Read the results. The page groups every sending source into three lists: sources that passed SPF and DKIM alignment, sources that probably belong to you but failed alignment, and unidentified sources. Each source gets a one-sentence verdict. Download the full results as a CSV file if you need them offline.
02 / FREQUENTLY ASKED QUESTIONS
Questions from people who read DMARC reports.
How do I get DMARC aggregate reports for my domain in the first place?
You need to publish a DMARC DNS record that includes an rua (reporting URI for aggregate reports) address. For example: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. Once that record is published, mailbox providers that honour DMARC will send daily aggregate reports to the address you specified. Dmarcread does not sign you up to receive reports or host a receiving address — it reads files you already have.
Why does a source appear in "probably yours" or "unidentified"?
A source is placed in "probably yours" when the report shows it failed SPF alignment or DKIM alignment, but its reported hostname matches a service Dmarcread recognises — Mailchimp, Salesforce, Zendesk, SendGrid, and several others. "Unidentified" means the hostname did not match any known service. In both cases, a verdict tells you which check failed (SPF, DKIM, or alignment). It is your decision whether the source is legitimate and needs authentication fixes, or is spoofing.
Can Dmarcread tell me if someone is spoofing my domain?
No tool can tell you that from a DMARC aggregate report alone. Dmarcread shows you which sources failed authentication checks and sorts them by recognisability. A source in "unidentified" could be a spoofing attempt — or it could be a contractor's newsletter tool, a forgotten dev server, or a service you use that was never configured to sign with DKIM. That judgment requires context you have and Dmarcread does not.
Does Dmarcread check DNS records or blocklists?
No. Dmarcread reads only what the report file contains. It does not query your SPF, DKIM, or DMARC records. It does not check any blocklist or reputation database. The tool cannot tell you whether your DNS records are correctly configured — that is outside the scope of a DMARC aggregate report.
I dropped in a file and the page says "no results" or nothing appeared.
The most common cause is file format. Dmarcread accepts .xml, .xml.gz, and .zip files exactly as received from your mailbox provider. If you extracted the XML from inside a ZIP before uploading, try uploading the original ZIP instead — Dmarcread decompresses archives automatically. Make sure the file is a valid DMARC aggregate report with a <feedback> root element. Some providers also send failure reports (forensic/FRF reports) which have a different XML structure — Dmarcread does not parse those.
How do I save or export the results?
Once results are displayed, click the Download CSV button above the results panel. The CSV file is generated entirely in your browser — no data is sent to any server. Results are not saved between visits; if you close the tab or refresh the page, everything is gone. Export to CSV before navigating away if you need to keep the data.
03 / KNOWN LIMITATIONS
What Dmarcread does not do — and what is not built yet.
Dmarcread is a browser-based DMARC aggregate report parser with a deliberately constrained scope. The following are not bugs — they are architectural boundaries or planned items that do not yet exist.
- No server-side processing. Everything runs in your browser. There is no backend, no database, no API, and no way to persist data between visits. This is by design — it enforces the privacy promise that your reports never leave your machine.
- No DNS or blocklist checking. Dmarcread cannot look up your SPF, DKIM, or DMARC records, nor check any blocklist or reputation database. It presents only what the report already contains.
- Cannot distinguish spoofing from misconfigured legitimate senders. Dmarcread reports what the receiving servers recorded. Whether a failing source is malicious or legitimate is your determination based on context.
- Known-services list is hardcoded and may be incomplete. The heuristic that places failing sources into "probably yours" uses a built-in list of email-sending services. If you use a service not on that list, it will appear as "unidentified" even if it is legitimate.
- Cannot diagnose email deliverability or spam classification. A DMARC aggregate report tells you which servers sent mail as your domain — not whether that mail reached the inbox. Those are separate problems.
- Pro tier does not exist yet. The Pro features described on the pricing page (auto-receipt of reports, scheduled digests, alerts, team access) require a backend server, a database, and an email sender — none of which exist in this product today. The Free tier is the complete working product.
- No DMARC policy management. Dmarcread cannot publish, change, or remove your DMARC DNS record, nor advise you on what policy to set.
04 / CONTACT US
How to reach a human.
If you have a question that is not answered here, or you need to report an issue with the tool, you can reach the team by email.
The dmarcread-p3 local part identifies which product your message is about so it reaches the right person. agen2ic.ai accepts mail at any local part. Expect a reply within one to two business days.
Before you email: Please check the FAQ above and the home page — your question may already be answered. If you are reporting a parsing issue, including the report file (or a sanitised excerpt) in your email helps us diagnose it faster.
There is no phone number, chat, or social media support route for this product. Email is the only channel.