Paste the contents of a DMARC aggregate report (the XML inside the .xml.gz / .zip attachment your rua= mailbox receives daily). We parse it locally and render the per-source-IP details: volume, SPF/DKIM result, alignment, disposition, and the receiver's failure reason when present. Same parser that powers PhishFence's ingest pipeline.
If you've published a DMARC record with a rua=mailto:... tag, mailbox providers (Google, Microsoft, Yahoo, etc.) send you daily aggregate reports as gzipped XML attachments. Open the .gz file, paste the inner XML here.
Don't have DMARC published yet? Start with the DMARC Record Generator (publishes a record at p=none so you collect data without affecting delivery), then come back here once your first reports arrive.
Want this automatic? PhishFence ingests aggregate reports for monitored domains, parses them, surfaces the same per-source breakdown plus IP enrichment (PTR, ASN, country) and LLM-driven root-cause analysis. Sign up free, monitor one domain forever.