What Is DMARC Report Analysis and Why It Matters for Deliverability

Imagine your domain is being used to send spam, phishing, or fake support emails — and you don’t know it until customers complain. That’s a real risk for any business. DMARC reports reveal who’s sending email from your domain, including unauthorized sources. But left unanalyzed, these reports are just raw data — a wall of XML you can’t read, ignore, or act on.

That’s where parsedmarc comes in. By setting it up yourself, you turn those reports into digestible insights. You see impersonation attempts, detect fraud early, and protect your sender reputation. This isn’t just about compliance — it’s about control. With a self-hosted parsedmarc setup, you automate visibility, reduce risk, and keep your domain trusted.

Key takeaways

  • DMARC reports reveal unauthorized email activity from your domain, including spoofing and phishing attempts.
  • Without parsing, reports remain unactionable — a passive data dump with no insight.
  • A self-hosted parsedmarc setup enables automated fraud detection, real-time monitoring, and long-term sender reputation protection.

How Does Parsedmarc Work with DMARC Data?

Parsedmarc takes raw DMARC aggregate (RUA) and forensic (RUF) reports from email receivers, parses their XML structure into clean, usable data like JSON or CSV, and exposes insights you can act on—like spotting alignment failures, tracking abuse trends, or triggering alerts. You can feed it reports via file, SMTP, or directly from your email gateway. Once parsed, you can analyze, filter, and visualize the data to harden your email infrastructure.

From XML to Actionable Intelligence

DMARC reports come in XML format, which is readable by machines but not humans. Parsedmarc does the heavy lifting: it reads each report, extracts sender IPs, domain alignment results, failure reasons (like SPF or DKIM mismatches), and message counts. You get structured data that’s easy to query, especially when you’re chasing down spoofing attempts or verifying that your mail infrastructure aligns correctly across domains.

Let’s say you receive a report showing unexpected traffic from an IP not in your approved list. Parsedmarc can flag that as a potential compromise. It’s not just about numbers—it’s about understanding intent. For example, a sudden spike in failures across multiple domains might indicate a phishing campaign using your brand’s name, even if your SPF or DKIM config is solid.

Flexible Input, Real-World Use Cases

Whether you’re using a self-hosted email system, a custom mailing pipeline, or an enterprise gateway, Parsedmarc can ingest reports from multiple sources. You can read local files, receive them via SMTP, or integrate with tools like Postfix, Exim, or custom scripts that forward reports. The modularity means you can build a real-time monitoring layer without relying on a third-party vendor.

DMARC is a feedback loop—its value only grows when you act on the data. Parsedmarc turns that feedback into measurable actions. For example, you can export reports as CSV and import them into a dashboard tool, or use them to validate your SPF/DKIM configurations over time. It’s the backbone of a self-hosted DMARC analysis setup.

When you’re not just monitoring but actively improving sender reputation, you’ll want accurate, real-time data. Tools like MailTester’s bulk email verification help you clean your list before sending, reducing the risk that your mail gets flagged—even if your DMARC setup is strong.

For deeper visibility into how your domain performs in real inboxes, consider tools that simulate real delivery conditions. MailTester’s inbox placement tests reveal how your email lands across major providers, giving you a clearer picture of your overall deliverability health.

Why You Should Set Up Parsedmarc Yourself — Not Rely on Cloud Tools

You should set up parsedmarc yourself because cloud-based DMARC tools often impose retention limits, restrict how frequently you get reports, or lock you into proprietary formats. Self-hosting removes those barriers, giving you full access to raw data, uninterrupted data retention, and control over how reports are processed and acted on. It also eliminates dependency on external service uptime or sudden policy changes.

Data Ownership and Long-Term Visibility

Many cloud DMARC analyzers only keep reports for 30 to 90 days, which is too short for meaningful trend analysis or auditing. With parsedmarc, you retain every report indefinitely—critical when investigating a breach, tracking phishing campaigns over time, or demonstrating compliance during an audit. You're not limited by vendor policies or hidden data expiration windows.

Integration and Operational Control

When you run parsedmarc in-house, you integrate it directly with your existing SIEM, ticketing systems, or monitoring tools—no need to wait for another vendor’s API to catch up. This means faster incident response and better visibility across your org's security stack. Cloud tools often require workarounds or third-party connectors, which add complexity and points of failure. Your data stays internal, and your processing pipeline is predictable, stable, and fully under your control.

Let’s be clear: cloud tools can be convenient. But they trade long-term utility for short-term ease. If you’re serious about email security, you don’t want to rely on an external service that might change its retention policy, shut down, or require a premium plan to access historical data. The RFC 7483 standard for DMARC reports was designed for this kind of self-service validation—built for systems that need to analyze, store, and act on data without intermediaries.

When you’re handling sensitive email data, especially for compliance-heavy industries, having direct control over your reporting pipeline isn’t a luxury. It’s necessary. The same discipline applies to email list hygiene—tools like bulk list verification ensure your outbound messages don’t trigger defensive measures due to invalid or risky addresses.

Ultimately, self-hosting parsedmarc isn’t about complexity. It’s about certainty: knowing your data is secure, your reports are complete, and your analysis isn’t held hostage by someone else’s uptime or business model. That level of control is what separates good email security from great.
Learn more about DMARC reporting standards in the official RFC documentation.

How to Install Parsedmarc on a Linux Server

You can set up parsedmarc on a Linux server by installing Python 3.9 or later, using pip to install the parsedmarc package, ensuring lxml is available for XML parsing, creating a low-privilege user for security, and configuring a systemd service to run it as a background daemon. This setup allows you to parse DMARC reports reliably and consistently, helping you detect email spoofing attempts and monitor sender reputation in real time.

Install the Required Dependencies

  1. Ensure your system has Python 3.9 or a newer version installed. Use your distribution’s package manager — for example, on Ubuntu, run sudo apt update && sudo apt install python3 python3-pip to install the latest available version.
  2. Install the lxml library, which parsedmarc uses to parse XML format DMARC reports. On Debian-based systems, use sudo apt install python3-lxml. Without this, parsedmarc will fail to process reports.
  3. Verify the installation by running python3 -c "import lxml; print('lxml installed')" to confirm the library is accessible.

Set Up the Parsedmarc Service

  1. Use adduser to create a dedicated system user with minimal privileges: sudo adduser --system --no-create-home --group parsedmarc. This improves security by isolating parsedmarc from other processes.
  2. Install parsedmarc via pip: sudo pip3 install parsedmarc. This downloads and configures the tool and its dependencies, including optional utilities for report analysis and formatting.
  3. Write a systemd service file to manage parsedmarc as a daemon. Create /etc/systemd/system/parsedmarc.service with the correct user, working directory, and command. The service should start on boot and log to a defined file.
  4. Enable and start the service with sudo systemctl enable parsedmarc and sudo systemctl start parsedmarc. Monitor logs with journalctl -u parsedmarc -f to ensure it runs without errors.

Once running, parsedmarc ingests DMARC aggregate reports sent to your organization’s reporting domain. It parses them into structured format, allowing you to analyze sender compliance, identify unauthorized senders, and detect policy violations. This is crucial for protecting your domain against phishing and spoofing attacks.

Install the Required DependenciesThe 3 steps described in “Install the Required Dependencies”, in order.1Ensure your system has Python 3.9 or a newer version installed. Use yourdistribution’s package manager — for example, on Ubuntu, run sudo aptupdate && sudo apt install python3 python3-pip to install the latestavailable version.2Install the lxml library, which parsedmarc uses to parse XML formatDMARC reports. On Debian-based systems, use sudo apt installpython3-lxml. Without this, parsedmarc will fail to process reports.3Verify the installation by running python3 -c "import lxml; print('lxmlinstalled')" to confirm the library is accessible.
The 3 steps described in “Install the Required Dependencies”, in order.

For organizations relying on verified sender data to prevent bounces and deliverability issues, tools like parsedmarc complement email validation systems. You can use MailTester’s email checker to validate email addresses before sending, reducing the risk of spam traps and improving reputation. If you’re processing large lists, bulk verification ensures your sender base remains clean and compliant. DMARC analysis works best when combined with accurate sender data.

Configuring Parsedmarc with Elasticsearch for Scalable Analysis

You can set up parsedmarc to analyze DMARC reports at scale by running Elasticsearch on a dedicated node with at least 8GB RAM, then directing parsedmarc output directly into the cluster using the --elasticsearch flag. This enables structured, queryable storage for long-term analysis of authentication results, alignment failures, and policy dispositions. For guidance on DMARC deployment best practices, refer to the IETF’s official specification in RFC 7483.

Set Up Elasticsearch for DMARC Data Ingestion

  1. Deploy Elasticsearch on a server with at least 8GB of RAM—use a dedicated node if possible. Performance degrades under high load with insufficient memory, especially when indexing large volumes of DMARC reports.
  2. Start Elasticsearch with default settings or pull the official Docker image for a clean, reproducible setup. The Docker image simplifies configuration and avoids dependency conflicts.
  3. Configure time-based index patterns to support efficient data retention and querying. Use index templates to apply consistent field mappings across time ranges, such as daily or weekly indices.
  4. Ensure your index mappings include key fields: source_ip, dkim_alignment, spf_alignment, disposition, and count. These allow you to track sender authentication, alignment status, and policy enforcement across domains.

Route Parsedmarc Output to the Cluster

Once Elasticsearch is ready, run parsedmarc with the --elasticsearch flag, pointing it to your cluster’s endpoint. This sends parsed reports directly into the index, skipping file-based storage and enabling real-time ingestion. If you're processing thousands of reports per day, this approach eliminates bottlenecks in manual parsing and reporting.

Using time-based indices ensures you can prune old data efficiently and maintain fast query performance over months or years. Most organizations find that monthly rollover indices strike a balance between retention and search speed. For teams managing multiple domains or large volumes of email traffic, this pipeline becomes essential for detecting spoofing campaigns and validating authentication setups consistently.

Consider pairing this setup with automated alerting in Kibana to flag recurring alignment failures or unexpected source IPs. This gives you visibility into potential abuse vectors before they impact deliverability. If you're verifying sender identities at scale, tools like MailTester’s bulk verification can help validate your email list quality—ensuring only deliverable addresses are sent, reducing bounce risks that could distort DMARC reports.

Parsing DMARC Aggregate Reports: Understanding the Output

When you run a parsedmarc setup, it turns raw DMARC XML reports into a clear, structured format. You get actionable insights: the date range of the report, the reporting source IP, and how each sender aligned with SPF and DKIM. For each email, it shows whether the message was marked for quarantine or rejected, and why—such as a missing or expired signature. This helps you spot real threats, not just noise.

What Each Record Tells You

Each parsed record reflects a single sender’s compliance with your DMARC policy. It shows if SPF passed, if DKIM was valid, and if both align with the domain in the From header. If alignment failed, parsedmarc marks it—commonly due to misconfigured subdomains or unauthorized third-party senders. The disposition outcome (none, quarantine, reject) confirms whether your policy actually enforced a result.

Many of the most common findings stem from real-world quirks: a subdomain sending without SPF alignment, an older DKIM key still in use, or a third-party platform (like a newsletter service) sending emails without proper authentication. These show up clearly in parsed output, even if the raw XML report buried them in verbosity.

Trimming the Noise from Raw Reports

Raw DMARC reports often include false positives—traffic from scanning tools, internal tests, or misconfigured mail servers. These can mislead you into thinking your domain is under attack or poorly secured. Parsedmarc filters out much of this noise by validating IP legitimacy and filtering known test sources.

For example, if a report shows 100 failed messages from an IP known to run scans (like a public email tester), parsedmarc can flag it as low risk. That’s one reason the output from a well-configured parsedmarc setup is far more useful than raw XML alone. It turns logging into a security and deliverability tool.

DMARC compliance isn’t about eliminating every failure—it’s about identifying which ones matter. You can use this output to tighten policies, audit external senders, or improve your SPF record. For a real-world example, RFC 7483 details how DMARC aggregate reports are structured and why parsing is essential.

When you’re managing deliverability at scale, consistency matters. Tools like parsedmarc bring structure to data that would otherwise be unusable. The goal is to spot weak links—like a forgotten subdomain or expired key—before attackers do. If you're checking whether your domains are correctly aligned in production, you can run a real-time check with MailTester’s email checker to validate sender-side configurations before they appear in reports.

Setting Up Monitoring and Alerts with Parsedmarc and Elasticsearch

You can set up real-time monitoring and alerts for your DMARC reports by parsing data with parsedmarc, indexing it in Elasticsearch, and using Kibana to visualize alignment failures, rejected messages, and top senders. Then, define thresholds—like over 50% SPF failure in a day—and trigger notifications via Elasticsearch Watcher or external tools like Prometheus with Alertmanager, routing them to Slack, PagerDuty, or your incident response system.

Build Visual Dashboards in Kibana

  • After parsing DMARC reports with parsedmarc, index the data into Elasticsearch using a standard pipeline.
  • Create a Kibana dashboard to track alignment failures, rejected messages, and the top sources of non-compliant mail (e.g., IP addresses or domains with high failure rates).
  • Use visualizations like time-series graphs and heatmaps to identify spikes in abuse or suspicious activity—common signs of spoofing attempts.
  • Filter by domain, authentication method (SPF, DKIM, DMARC), and report date to isolate recurring issues.

Configure Alerts and Integration

  • Set up threshold-based alerts in Elasticsearch Watcher: for example, trigger a notification if SPF failures exceed 50% for a domain in a 24-hour period.
  • Alternatively, use Prometheus with Alertmanager for greater scalability, especially in larger environments, and integrate with your existing monitoring stack.
  • Forward alerts to Slack channels, PagerDuty incidents, or email teams using webhooks or direct API integrations.
  • Use established practices from RFC 7483 (DMARC) and guidelines like those from the M3AAWG to validate your alert thresholds and avoid false positives.
  • Regularly review alert history and tune thresholds to reduce noise—too many false alerts degrade trust in the system.

For teams managing large lists, pairing this setup with tools that validate sender address integrity upfront—like bulk email verification—can reduce the number of reports from misconfigured or invalid senders in the first place. Always test alert logic in a staging environment before pushing to production.

Integrating Parsedmarc Output with Email Deliverability Workflows

You can use parsed DMARC reports to pinpoint unauthorized senders, verify third-party compliance, prune bad domains from your lists, and track sender reputation health over time—turning raw reports into action. Let's walk through how.

Turning DMARC Data into Actions

  • Parse your DMARC reports using parsedmarc to identify domains or IPs sending mail without your authorization, especially those failing SPF or DKIM alignment.
  • Review the results to determine if legitimate senders are failing alignment—update your SPF record to include valid sources or adjust DKIM signing policies accordingly.
  • Share the findings with internal teams (like marketing or operations) to confirm that third-party vendors (e.g., CRM, email platforms) are sending on your behalf with proper authorization.
  • Use repeated failures as a signal to remove domains or subdomains from your email list—specifically those that consistently fail alignment or show up in failure reports over multiple weeks.

Monitoring and Long-Term Health

  • Track the number of DMARC-aligned failures over time. A downward trend indicates improved sender compliance and stronger reputation.
  • Compare this against your email deliverability metrics—such as inbox placement rates and spam complaints—to correlate report data with actual delivery outcomes.
  • Set up automated alerts for new or recurring failed reports through tools like Spamhaus or RFC 7483, which define DMARC reporting standards.
  • Pair this with regular list hygiene practices: use tools like MailTester’s bulk verification to test existing lists before sends and catch invalid or compromised addresses early.

When you integrate parsedmarc output with your email workflows, you’re not just collecting data—you’re using it to reduce abuse, clean up your sender profile, and improve inbox placement. This approach keeps your domain secure and your reputation strong.

Common Pitfalls in Parsedmarc Setup and How to Avoid Them

You’re setting up parsedmarc to analyze DMARC reports, but common issues like running it as root, outdated Python deps, or ignoring RUF reports can break your visibility into threats. Let’s fix them before they compromise your email security posture.

Security and Compatibility Mistakes

  • Don’t run parsedmarc as root. Use a dedicated, non-privileged user to minimize risk if the tool is compromised — this is a baseline security practice.
  • Verify your Python and lxml versions are compatible with parsedmarc. Some older versions of lxml are known to break parsing of large or malformed reports.
  • Don’t skip testing with a sample report. Run parsedmarc on a real, signed DMARC report from your domain to verify it processes the data correctly before full deployment.

Data Retention and Threat Visibility

  • Store raw DMARC reports for at least 90 days. You’ll need them to trace phishing campaigns or validate changes to your email policy — forensic data doesn’t always come back.
  • Ignore RUF reports at your peril. They contain full headers and payloads from failed emails, often revealing impersonation attempts. Tools like parsedmarc can extract this data but only if you enable RUF parsing and store the raw data.
  • Don’t assume every report is valid. Filter out false positives from tools like mail testers or spam traps using known-good domains, and monitor for consistent patterns of spoofing.

For teams validating email addresses before sending, even a small number of invalid or risky addresses can hurt deliverability. Use a reliable email verification service like bulk email verification to clean your list and reduce bounce risk before deployment.

Even small deviations in setup can let threats slip through — consistency in data handling is not optional.

For advanced analysis, consider how DMARC data fits into broader sender reputation. Real-time email testing via tools like inbox placement testing can help spot issues that DMARC alone might miss.

How MailTester Complements DMARC Analysis Without Replacing It

You don’t need MailTester to parse DMARC reports—those require specialized tools like parsedmarc or DMARC analyzers. But you do need it to ensure your sending list is clean. Invalid, disposable, or role-based addresses increase spam risk, which can trigger DMARC failures even if your authentication is technically correct. Let’s make sure your list is as strong as your headers.

Why Your List Quality Affects DMARC Results

Even if your SPF, DKIM, and DMARC records are set up perfectly, poor list hygiene can still hurt your reputation. Sending to invalid or disposable addresses often leads to bounces, high complaint rates, and blacklisting—all of which DMARC reports catch. A poor sender reputation can result in misalignment or reduced reporting accuracy, making it harder to distinguish real threats from noise.

When your list is full of risky addresses, you’re essentially sending signals to email providers that you don’t control your senders. That can trigger aggressive filtering, even if your domain alignment is technically perfect. Real-world metrics from sources like Spamhaus show that sender reputation remains a key factor in inbox placement, even when authentication is correct.

MailTester’s Role in Strengthening Your DMARC Foundation

MailTester doesn’t read DMARC reports or analyze aggregate data. Instead, it works upstream—before you send. It checks individual email addresses in your list for validity, role accounts, disposable domains, and catch-all setups. You can run this at scale with our bulk verification, or integrate it in real time via our verification API.

For example, removing role addresses like admin@, support@, or sales@ reduces the chance of accidental spam complaints. Catch-all domains don’t help deliverability—they just absorb traffic and hurt your sender reputation. Disposables are almost always short-lived and used for abuse. Filtering them out doesn’t just lower bounce rates—it improves your overall deliverability, which supports stronger DMARC alignment.

Think of it this way: a clean list leads to better inbox placement, which means more consistent engagement. That, in turn, strengthens your sender reputation and gives you more reliable, accurate DMARC reports. You’re not replacing parsedmarc—you’re making sure the data it sees reflects real, intentional delivery.

You can test your email’s inbox placement with our inbox tester to see how your clean list performs in real inboxes. With 98.9% accuracy, MailTester helps you send only to addresses that are likely to receive and engage—making your DMARC analysis more meaningful, not less.

Final Thoughts: Building a Robust Email Security and Delivery Foundation

DMARC is only effective when its reports are analyzed. Without parsing, the data remains unusable. Parsedmarc enables scalable, automated analysis of DMARC reports, turning raw data into actionable insight.

Self-hosting parsedmarc provides full control over data and workflows, but requires ongoing maintenance. For teams without dedicated infrastructure, cloud-based tools may offer a lower-effort alternative. Evaluate the trade-off between ownership and operational cost.

Complement technical controls like DMARC with strong list hygiene. Use MailTester to catch invalid, disposable, and risky addresses before sending. This reduces bounces, lowers spam complaint rates, and improves inbox placement.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

What does parsedmarc do with DMARC reports?

Parsedmarc parses XML-formatted DMARC aggregate and forensic reports, converting them into structured data for analysis, alerting, and visualization.

Is parsedmarc easy to install on a VPS?

Yes, parsedmarc installs via pip with minimal dependencies. It runs cleanly on a Linux VPS with Python 3.9+ and basic networking.

Can I use parsedmarc without Elasticsearch?

Yes. Parsedmarc outputs to CSV or JSON. Use Elasticsearch only if you need scalable querying over large volumes of data.

Why do DMARC reports show unauthorized sends from my domain?

This usually indicates unauthorized third-party systems sending mail using your domain, misconfigured mail services, or phishing attempts.

How often should I analyze DMARC reports?

Daily analysis is recommended to catch abuse early. Weekly is the minimum for meaningful detection of trend changes.

Does MailTester help with DMARC compliance?

Not directly. MailTester improves list quality, which indirectly supports sender reputation and reduces the risk of DMARC failures.

What’s the difference between SPF and DKIM alignment in DMARC?

SPF alignment checks if the envelope-from value matches the sender domain. DKIM alignment checks if the domain in the DKIM signature matches the header-from.

Can parsedmarc detect phishing attempts?

Yes, forensic reports (RUF) contain full message headers. Parsedmarc can extract these and flag suspicious patterns, like spoofed sender addresses.

How long should I retain DMARC reports?

Keep raw reports for at least 90 days. Long-term retention supports forensic analysis and compliance audits.

What’s the cost of setting up parsedmarc?

The tool is free. Costs come from infrastructure: a modest VPS, storage, and time to maintain the system.

Can I use MailTester to verify domains in DMARC reports?

No. MailTester verifies email addresses, not domains or DMARC records. It can help validate addresses found in reports as part of list hygiene.

Is parsedmarc compatible with all email providers?

Yes. As long as the receiving provider sends DMARC reports to your RUA address, parsedmarc can process the data regardless of the sending service.