Blog · Dmarc
Where Do DMARC Reports Get Delivered? A Plain-English Guide
The short answer: DMARC reports are emails
DMARC reports do not appear in any admin console, web portal, or dashboard by default. They are sent as email messages to addresses you specify inside your own DMARC DNS record.
That surprises a lot of people. You spend time configuring DMARC, you think there should be a screen somewhere showing your authentication results. There is not. DMARC reporting is email-based, and it has been since the protocol was designed.
The reports arrive as gzip-compressed XML files attached to ordinary emails. Receiving mail servers -- the servers at Gmail, Microsoft, Apple, and everyone else you exchange mail with -- send these reports to the addresses you declare in your DMARC record.
---
What the rua and ruf tags do
Your DMARC record contains two tags that control where reports go.
rua stands for Reporting URI for Aggregate. Aggregate reports arrive once per day from each receiving server. They are a summary: how many messages from your domain passed or failed DMARC, and which servers saw them. They do not contain message content, only metadata. Think of them as a daily digest of your domain's email health across the entire internet.
ruf stands for Reporting URI for Forensic. These are failure reports, sometimes called forensic reports. They are sent immediately when a specific message fails DMARC checks. Unlike aggregate reports, they are not sent by every receiver -- they are only triggered for messages that a receiving server decides to report on. Most large providers do not send failure reports at all. Google, Microsoft, and Apple all suppress ruf reports in practice.
A typical DMARC record looks like this:
v=DMARC1; p=none; rua=mailto:reports@example.com; ruf=mailto:failures@example.com
The mailto: prefix tells the receiving server where to send the report. That email address is where your DMARC data arrives.
---
Why you might not be receiving DMARC reports
This is the part most articles skip. Here are the actual reasons reports go missing.
Spam filters eat the reports. DMARC reports arrive from external mail servers you have never exchanged mail with before. Their messages land in your spam folder because they come from unfamiliar sources, contain XML attachments, and a machine generated subject line. Check your spam folder first. Create a filter that lets DMARC reports through.
The receiving mailbox does not exist or is over quota. If reports@example.com is not a real mailbox, the reports disappear. If the mailbox is full, the receiving server holds them temporarily and eventually stops trying. Make sure the target address is active and has space.
The reports go to the wrong domain. The rua address must be a reachable email domain. If you own example.com but put reports@otherdomain.com in your DMARC record, those reports go to otherdomain.com -- which you may not even monitor. Many organizations use a dedicated subdomain like dmarc-reports@example.com to keep reports separate from normal mail flow.
Your domain's DMARC record is misconfigured. If the rua tag points to an address at a domain that does not have a valid MX record, receiving servers cannot deliver the report and will silently fail. Verify your target domain can receive mail before using it in a DMARC record.
Receiving servers are not sending reports at all. Not all mail providers send DMARC reports. Some large consumer providers suppress aggregate reports, and almost all of them suppress failure reports. If you send mostly to Gmail addresses, your aggregate data from Google will be comprehensive. If you send mostly to small business servers that barely implement SMTP, you may receive very few reports. This is a known gap in the DMARC ecosystem.
---
How to fix missing DMARC reports
Work through this checklist in order.
1. Check your spam folder for reports with subjects like "DMARC Aggregate Report" or "Feedback Report."
2. Look at your DMARC record and identify the rua and ruf email addresses. Make sure those are real, monitored mailboxes.
3. Verify the receiving domain has valid MX records and can receive external mail.
4. Create a spam filter rule to whitelist emails with "DMARC" or "Feedback Report" in the subject.
5. If you manage multiple domains or subdomains, check that each one has its own rua entry in its DMARC record. Aggregate reports are only sent for the domain they are published on.
6. Route your DMARC reports to a dedicated inbox or aggregation tool. Services like DMARCFlow connect to your report email address and parse the XML into a readable dashboard, so you do not have to manually filter spam or hunt through attachments to find what failed.
If you have done all of this and you are still not receiving reports, the most likely explanation is that the other side is not sending them. DMARC reporting is voluntary at the receiver side. There is no enforcement mechanism that requires mail providers to send reports.
---
Getting reports without the email hassle
Managing DMARC reports by email works until you have more than one domain. Then the volume of XML attachments becomes difficult to track manually.
This is the core problem DMARCFlow solves. It connects to your report email address via forwarding or API, parses all incoming XML into a structured dashboard, and gives you aggregate data across all your domains in one place. Failure reports surface as alerts instead of sitting in a spam folder.
For teams running DMARC across multiple domains, reading reports by email is the part that breaks first. A dedicated aggregation layer means you actually see the data DMARC generates, which is the whole point of running it.
---
FAQ
Do DMARC reports go to my regular email inbox?
They go to whatever email address you specify in your DMARC record. That can be your regular inbox, but many people set up a dedicated address or subdomain to keep DMARC reports separate from normal mail.
What is the difference between rua and ruf?
rua delivers aggregate reports once per day. ruf delivers failure reports immediately when a message fails DMARC. Most consumer mail providers do not send ruf reports, so most people only receive rua reports.
How often are DMARC aggregate reports sent?
Typically once per day per receiving server. If you exchange mail with 20 different mail providers, you could receive up to 20 aggregate reports per day, one from each provider.
Why am I not receiving DMARC failure reports?
Most large mail providers, including Google, Microsoft, and Apple, do not send ruf (failure) reports. This is a deliberate decision on their part. You can receive aggregate reports from them, but not forensic failure reports.
Can I use a free email address for DMARC reports?
Technically yes, but it is not recommended. Using a free provider means your reports go to an external service you do not control, and some providers may block or filter the reports. A dedicated subdomain or your own mail infrastructure is more reliable.