Solution · DMARC Reports

DMARC monitoring.Who sendsin your name?

Conbool ingests the DMARC reports of all receiving systems, classifies every sending source and shows what needs to be resolved before a stricter policy.

Why DMARC without analysis has no effect

A DMARC record with p=none only collects data. The value appears once someone reads it.

Reports are XML in archives

Receiving systems send compressed XML files every day. In practice nobody reads them in a mailbox.

Unknown senders

Newsletter service, ticket system, accounting: many systems send in the name of the domain without IT knowing.

Missing or third-party report address

Many records carry no report address at all or that of a former vendor. The analysis then stays empty.

No signal on abuse

A phishing wave with a forged sender shows up in the reports first. Without analysis it goes unnoticed.

How the monitoring works

Three steps, then collection and analysis run on their own.

1. Enter the report address

Every tenant receives a fixed report address. The wizard shows the record or sets it via Domain Connect where the DNS provider supports it. Existing addresses are kept.

2. Reports are ingested

Aggregate and forensic reports are accepted, unpacked and analysed. Nothing is delivered to a mailbox.

3. Classify sources, work through findings

Every sending source appears with provider, origin and the result of SPF and DKIM. Recommendations name the next step.

What the monitoring delivers

DMARC Reports is included in every suite.

Pass rate over time

Trend per domain with comparison to the previous period, for freely selectable time ranges.

Sending sources classified

Known sending services are recognised and named. Unknown sources are listed separately and can be reviewed.

SPF and DKIM per source

Alignment and result of both mechanisms per sender, including the DKIM selector used.

Recommendations with severity

Rules from the SPF lookup limit to weak DKIM keys. Resolved findings close themselves.

Alerts and weekly report

Critical findings go by email to the configured recipients, plus a regular summary report.

Forensic reports

Individual reports are captured with headers where receiving systems provide them.

Analysis with and without Conbool

What changes day to day.

 
Conbool DMARC Reports
Reports in a mailbox
Readability
Analysis with trend, sources and findings
XML files in ZIP and GZIP archives
Sender classification
Recognised services with name and origin
IP addresses without context
Response to abuse
Email alert on critical findings
Noticed only after complaints
Basis for p=reject
Assessment of whether the next level is safe
Estimate
Data path
Processing at Conbool, operated in Germany
Additional tool with its own contract
Licence
Included in every suite
Separate subscription per tool

As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.

DMARC monitoring FAQ

What is DMARC monitoring?
The continuous analysis of the reports that receiving systems send to the address named in the DMARC record. It shows which systems send in the name of a domain and whether SPF and DKIM pass.
Does Conbool have to be the mail path?
No. The report address in the DMARC record is sufficient for the analysis. Reports are ingested independently of the mail path.
Can an existing DMARC tool run in parallel?
Yes. A DMARC record can carry several report addresses. Existing addresses are kept during setup.
How long are reports retained?
Configurable per tenant between 30 and 365 days, 90 days by default. After that the data is deleted.
What does the monitoring cost?
DMARC Reports is included in every suite. Ongoing enforcement and maintenance are handled by DMARC Manager, which is available as an add-on to every suite and is billed per domain.
Who may see the analysis?
Access follows the role model of the tenant. Reading and changing are separate permissions, and changes are recorded in the audit log.

See who sends in your name.

Included in every suite. Analysis from the first report.