Parse and automate DMARC aggregate (rua) report ingestion

domain: dmarcreport.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Add a rua=mailto:reports@yourdomain.com (or a dedicated third-party ingestion address) to your DMARC record so receiving servers know where to deliver daily XML reports.
  2. Receiving servers send gzip-compressed XML attachments (.xml.gz or inside a .zip) once per day; set up a mailbox rule or IMAP fetch to land these in a processing folder.
  3. For self-hosted parsing, use the open-source parsedmarc tool: it reads the XML schema, extracts per-source IP rows (spf_result, dkim_result, disposition, count), and can forward structured data to Elasticsearch or a Kafka topic.
  4. Map each source IP to a known ESP or internal mail server using PTR lookups and a maintained allowlist; flag unknown IPs for investigation.
  5. Build alerting on disposition=quarantine or disposition=reject rows with count > threshold to catch misconfigured or rogue senders quickly.
  6. Archive raw XML for at least 30 days and retain parsed records for trend analysis; correlation across providers reveals SPF alignment gaps that single-provider views miss.

Known gotchas

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans