Emails processed
Every message from the aggregate reports over the selected period, by outcome. The tabs slice the same data four ways: overall DMARC status, the two aligned mechanisms separately (a source failing SPF but passing DKIM is the classic forwarder signature; failing both is either spoofing or a badly misconfigured sender), and what receivers actually did with the mail (disposition). SPF/DKIM here are the aligned results receivers evaluated for DMARC, not raw authentication.
Volume trend
Daily message volume stacked by classification — green direct, amber forwarded, red threat/unknown. A growing red band is the picture of a spoofing campaign; hover for the exact split.
Alignment trend vs the enforcement gate
Daily aligned-pass rate against the 98% readiness gate (dashed) — watch yourself converge on enforcement instead of reading a static verdict.
Enforcement readiness
Codified version of dmarcian's published gate: aligned-pass rate ≥ 98% over a rolling 28-day
window (per-domain configurable via dmarc_alert_config). The checkbox controls the second gate —
whether a full window of data must have been collected before a domain can read Ready. Untick it when you
already know the domain's sending cycles and don't want to wait out the observation period; the aligned-pass
gate still applies to whatever data the window holds. A verdict, not an action — when to actually move
p=none → quarantine → reject stays your call. Evaluated on fixed windows, independent of the
period selector above.
Volume breakdown
Direct = aligned SPF pass (mail that took the direct path intact). Forwarded = aligned DKIM pass with SPF fail — the classic forwarding signature; still passes DMARC. Threat/unknown = neither aligned mechanism passes — mail claiming the domain that DMARC would act on.
New sending sources
Source IPs seen for the first time ever per domain, within the selected period. A brand-new source failing alignment is the classic spoofing signature — those also trigger a one-shot email alert (aligned new sources are listed here but not emailed).
Top sending sources
Each source is classified (known sender / SPF-authorized / Unknown) and, where available, enriched with its reverse DNS, network (ASN), and country via ipinfo.io — cached for 30 days per IP. "Unknown" sources from an unexpected network or country are the ones worth investigating first.
Recent aggregate reports
Forensic incidents (RUF)
Each forensic (RUF/ARF) sample, correlated where possible against the aggregate (RUA) volume it's part of — same source IP, same domain, arrival time inside that report's own period. No vendor reviewed in the research behind this tool does this automatically. RUF volume is near-zero industry-wide (most large mailbox providers stopped sending it for privacy reasons), so this is "when available," not a primary workflow — every sample is shown whether or not a match is found.