How report ingestion works
DMARC aggregate reports are XML emails that mailbox providers (Google, Yahoo, Microsoft…) send to the address in your domain's rua= tag — usually daily, sometimes zipped. DmarcDuck turns them into your dashboard.
1.Add the domain in your dashboard
/api/ingest/YOUR-TOKEN. That token is the only credential needed for reports; rotate it by removing and re-adding the domain.2.Get reports delivered to that URL
The recommended zero-cost path: Cloudflare Email Routing (free). Create a route from an address like dmarc@ingest.yourdomain.com to a tiny Email Worker that POSTs the attachment to your ingestion URL. We provide the worker code in the repository README — about twenty lines.
Alternative: any automation (n8n, GitHub Actions, a cron script) that fetches reports from a mailbox and POSTs the raw XML or the zip to the URL. The endpoint accepts raw XML bodies and multipart file uploads, so almost anything can deliver.
3.Set your rua (if you haven't)
Your DNS record routes reports to your forwarding address:
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc@reports.your-forward-domain.com; fo=1"
Providers start sending within 24–48 hours of the record propagating.
Privacy stance
Aggregate reports contain no message content — they are summaries of which IPs sent how much mail claiming to be your domain, and whether it authenticated. We store exactly that, tied to your domain, and delete everything when you remove the domain. The free analyzer keeps nothing beyond a 7-day-expiring share link, and only if you choose to share it.
Create an account to set up a domain, or try the analyzer first.