10:50:52 | records: 37578 | dups: 0 | errors: 1 | sources: cache:37578 messages:0 | imap status: idle | last imap fetch: 10:50:49
clear
records
14
parse errors
1
unique source IPs
1
report date range
2026-07-07 — 2026-09-10 02:00:00

Top 10 source IPs

networkcount
MSFT 19

Top 10 header-from domains

domaincount
weasel.example.com 16
yak.example.com 3

Phase 1 — Discovery: who is sending mail from your domains? You have published p=none and are collecting data. Nobody is being blocked yet.

Focus on message volume, not IP count — a source sending 50 000 messages is urgent; one sending 3 is noise.

Both-fail sources (DKIM fail AND SPF fail) are either spoofing attempts or services that were set up without telling you. Surface these first.

Expand a domain, then open "By source IP" to see the quadrant breakdown per prefix group.

Sender landscape
both pass SPF fail DKIM fail both fail
weasel.example.com 16
94%
MSFT total 16
IP PTR Total DMARC failures share
2603:10a6:20b:5d4::20 16
Enterprise Outlook total 16

Top 10 failing source IPs

countsource IPPTR
15 2603:10a6:20b:5d4::20
domaindispdkimspf#
weasel.example.comrejectfailfail15
source IPheader-fromcount dispositionDKIMSPFreport begin
2603:10a6:20b:5d4::20 weasel.example.com 1 none pass fail 2026-07-07 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-07-13 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-07-28 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-08-01 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-08-11 02:00
2603:10a6:20b:5d4::20 weasel.example.com 2 reject fail fail 2026-08-17 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-08-18 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-08-21 02:00
2603:10a6:20b:5d4::20 weasel.example.com 2 reject fail fail 2026-08-22 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-08-23 02:00
2603:10a6:20b:5d4::20 weasel.example.com 2 reject fail fail 2026-08-28 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-09-03 02:00
2603:10a6:20b:5d4::20 weasel.example.com 1 reject fail fail 2026-09-10 02:00
yak.example.com 3
100%
MSFT total 3
IP PTR Total DMARC failures share
2603:10a6:20b:5d4::20 3
Enterprise Outlook total 3

Top 10 failing source IPs

countsource IPPTR
3 2603:10a6:20b:5d4::20
domaindispdkimspf#
yak.example.comrejectfailfail3
source IPheader-fromcount dispositionDKIMSPFreport begin
2603:10a6:20b:5d4::20 yak.example.com 3 reject fail fail 2026-07-30 02:00

Phase 2 — Hardening: what would break if you tightened the policy? You understand your sender landscape and want to move from p=none toward p=quarantine or p=reject. The risk is collateral damage to legitimate mail.

Policy readiness % = share of messages that would survive a reject policy today.

SPF-only sources need DKIM signing added in their sending platform.

DKIM-only sources need their SPF record aligned with your From: domain.

No DMARC alignment sources send all mail failing — configure or block.

Inconsistent sources have mixed results — investigate per-IP.

DMARC readiness
both pass SPF fail DKIM fail both fail
weasel.example.com 16 / 16
94%
MSFT 16 / 16
IP PTR Fail / Total DMARC failures share
2603:10a6:20b:5d4::20 16 / 16

inconsistent — some records fail

Enterprise Outlook total 16

Top 10 failing source IPs

countsource IPPTR
15 2603:10a6:20b:5d4::20
domaindispdkimspf#
weasel.example.comrejectfailfail15
source IPheader-fromcountdispositionDKIMSPFreport begin
2603:10a6:20b:5d4::20weasel.example.com1none pass fail 2026-07-07 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-07-13 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-07-28 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-01 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-11 02:00
2603:10a6:20b:5d4::20weasel.example.com2reject fail fail 2026-08-17 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-18 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-21 02:00
2603:10a6:20b:5d4::20weasel.example.com2reject fail fail 2026-08-22 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-23 02:00
2603:10a6:20b:5d4::20weasel.example.com2reject fail fail 2026-08-28 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-09-03 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-09-10 02:00
yak.example.com 3 / 3
100%
MSFT 3 / 3
IP PTR Fail / Total DMARC failures share
2603:10a6:20b:5d4::20 3 / 3

no DMARC alignment

Enterprise Outlook total 3

Top 10 failing source IPs

countsource IPPTR
3 2603:10a6:20b:5d4::20
domaindispdkimspf#
yak.example.comrejectfailfail3
source IPheader-fromcountdispositionDKIMSPFreport begin
2603:10a6:20b:5d4::20yak.example.com3reject fail fail 2026-07-30 02:00

Phase 3 — Steady state: did something break? Is anyone spoofing you? You have a tight policy in place (p=quarantine or p=reject). Watch for anomalies.

New sources — an IP appearing for the first time in the last 30 days that was not seen before. Could be a new legitimate sender nobody configured, or the start of a spoofing campaign.

Active failures — sources still failing DMARC under a strict policy in the last 30 days. Persistent failures with high volume are either spoofing or a misconfigured legitimate service that needs fixing.

If a major reporter (Google, Microsoft) stops appearing, your rua= address may be bouncing.

Alignment health — last 30 days
both pass SPF fail DKIM fail both fail
07-07
07-13
07-28
07-30
08-01
08-11
08-17
08-18
08-21
08-22
08-23
08-28
09-03
09-10
weasel.example.com 16 / 16
94%
07-07
07-13
07-28
07-30
08-01
08-11
08-17
08-18
08-21
08-22
08-23
08-28
09-03
09-10
MSFT new failing 16 / 16
IP PTR Fail / Total DMARC failures share
2603:10a6:20b:5d4::20 15 / 16
Enterprise Outlook total 16

Top 10 failing source IPs

countsource IPPTR
15 2603:10a6:20b:5d4::20
domaindispdkimspf#
weasel.example.comrejectfailfail15
source IPheader-fromcountdispositionDKIMSPFreport begin
2603:10a6:20b:5d4::20weasel.example.com1none pass fail 2026-07-07 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-07-13 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-07-28 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-01 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-11 02:00
2603:10a6:20b:5d4::20weasel.example.com2reject fail fail 2026-08-17 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-18 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-21 02:00
2603:10a6:20b:5d4::20weasel.example.com2reject fail fail 2026-08-22 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-08-23 02:00
2603:10a6:20b:5d4::20weasel.example.com2reject fail fail 2026-08-28 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-09-03 02:00
2603:10a6:20b:5d4::20weasel.example.com1reject fail fail 2026-09-10 02:00
yak.example.com 3 / 3
100%
07-07
07-13
07-28
07-30
08-01
08-11
08-17
08-18
08-21
08-22
08-23
08-28
09-03
09-10
MSFT new failing 3 / 3
IP PTR Fail / Total DMARC failures share
2603:10a6:20b:5d4::20 3 / 3
Enterprise Outlook total 3

Top 10 failing source IPs

countsource IPPTR
3 2603:10a6:20b:5d4::20
domaindispdkimspf#
yak.example.comrejectfailfail3
source IPheader-fromcountdispositionDKIMSPFreport begin
2603:10a6:20b:5d4::20yak.example.com3reject fail fail 2026-07-30 02:00