How to read your DMARC reports
Add your domain to the DMARC monitor, point the reports at SpamCipher, and see who is sending as you
Updated 11 October 2026
DMARC reports are what mail providers send back about every message that used your domain: whether it passed SPF and DKIM, and where it came from. Read together, they show you who is sending as your domain, including the services you forgot about and anyone pretending to be you. SpamCipher collects the reports, turns them into one compliance figure per domain, and tells you what to fix before you move the policy to reject.
Before you start
- Access to your domain's DNS, to add the record the wizard gives you
- About 6 minutes, then a few days for the first reports to arrive
Add the domain
Step 1: Open DMARC
- Open Plan & Usage at the top right and click Manage DMARC under Monitoring.
Step 2: Run the Setup Wizard
- Click Setup Wizard at the top, type your domain under Domain name and click Add Domain.
- The wizard reads your existing DMARC, SPF and DKIM records and tells you what is there.
Step 3: Point the reports at SpamCipher
- Under Configure DNS, the wizard shows the DMARC record to publish, with a reporting address that belongs to your workspace.
- Add it at your DNS host, come back and click the check. From then on, every provider that handles your mail sends its reports here.
Read the reports
Step 4: Watch the domain's state
- Under Domains, each domain shows its Status, its Policy (none, quarantine or reject), its Compliance (the share of messages that passed) and how many messages the reports covered.
- Pending means the record is not published yet or no report has arrived; the first reports take a day or two.
- Click View on the domain to see every source that sent as it, with its pass rate.
Step 5: Read a report you were sent
- A report that reached your own inbox can be read here too. Click Upload report and choose the file; it is added to the domain's figures.
Troubleshooting
The domain stays Pending
The DMARC record is not published, or it names a different reporting address. Open the Setup Wizard again and compare the record it shows with what your DNS host has.
Compliance is low but my campaigns pass
Another service sends as your domain without SPF or DKIM: a CRM, a help desk, a newsletter tool. Click View on the domain to see the sources, then add each real one to your SPF record and turn on its DKIM.
When can I move to reject?
When compliance has sat near 100% for two weeks and every source in the list is one you recognise. Move to quarantine first and watch for another week.
Did this answer your question?