Use DMARC Reports to Find Unauthorized Email Senders
DMARC reports provide a practical view of which systems send messages claiming to represent your domain. They can reveal legitimate providers you forgot to document, misconfigured infrastructure, forwarding paths, and completely unauthorized services attempting to use your brand.
The most useful reports are aggregate reports, usually delivered as XML files. They summarize sending IP addresses, authentication results, and the policy applied to each message stream. With a consistent review process, these records become an inventory of your real email ecosystem and an early warning system for spoofing.
Understand What DMARC Reports Show
Aggregate reports identify the reporting organization, the domain being evaluated, the sending IP address, message volume, and the results of SPF and DKIM checks. They may also show whether DMARC alignment succeeded, which is important because a message can pass SPF or DKIM while still failing alignment with the visible From domain.
A single IP address does not always identify a specific vendor. Cloud platforms, marketing tools, ticketing systems, and email forwarding services may use shared infrastructure. Treat each IP as a clue that must be matched with DNS records, vendor documentation, message headers, and internal ownership records.
Build a Reliable Sender Inventory
Begin by grouping report data by sending IP, authenticated DKIM domain, SPF domain, and message count. Look for recurring patterns over several reporting periods rather than reacting to one isolated event. A low-volume sender may be a legitimate password-reset system, while a high-volume unfamiliar source deserves faster investigation.
Compare these findings with your known providers, including marketing automation, customer support, payroll, CRM, transactional email, and Microsoft 365 or Google Workspace services. If your organization relies on forwarding, review email forwarding service trust and authentication behavior because forwarding can alter SPF results or expose gaps in your configuration.
Separate Legitimate Services From Abuse
An unknown sender is not automatically malicious. It might be a recently adopted SaaS platform, a subsidiary, a regional office, or an outsourced agency that was never added to the security inventory. Confirm the sender through procurement records, application owners, DNS administrators, and the vendor’s published sending requirements.
Warning signs include large volumes from unfamiliar hosting providers, repeated DMARC failures, changing IP addresses, forged DKIM selectors, and activity that begins suddenly after a domain is publicly promoted. An unauthorized service may be sending phishing messages, testing your domain’s reputation, or exploiting a forgotten system with valid credentials.
| Report finding | Likely explanation | Recommended action |
|---|---|---|
| Known vendor, aligned SPF or DKIM | Authorized sending service | Document it and monitor authentication |
| Known vendor, repeated alignment failure | Configuration or forwarding issue | Check DNS, return paths, and DKIM setup |
| Unknown IP with low volume | Forgotten application or isolated abuse | Identify the owner and inspect headers |
| Unknown IP with high volume | Unauthorized provider or compromise | Investigate quickly and consider containment |
| Multiple IPs using one DKIM selector | Shared or changing infrastructure | Verify vendor ownership and selector design |
Investigate Authentication Failures
Review SPF failures alongside the envelope-from domain and DKIM results. SPF can fail when a service is missing from the authorized record, when forwarding changes the connecting IP, or when the SPF record exceeds DNS lookup limits. Adding every unfamiliar IP immediately can create an overly broad policy and increase future abuse.
DKIM failures require a different investigation. Check whether the selector exists, whether the public key is valid, and whether the signed domain aligns with the visible From domain. A service that passes DKIM but uses an unrelated signing domain may still fail DMARC alignment, indicating incomplete setup rather than definite fraud.
Use History to Detect Emerging Risk
DMARC data becomes more valuable when retained over time. Establish a baseline for normal senders, daily or weekly volume, and expected authentication outcomes. New sources can then be compared with established behavior instead of being judged without context.
Correlate reports with message samples, mail gateway logs, and domain reputation checks. Bulk review is useful when an organization owns many domains or has acquired new brands; screen vendor security checks can help compare authentication posture across related sending environments.
Respond With Controlled Changes
When a sender is confirmed as legitimate, update its SPF or DKIM configuration according to the provider’s documented requirements, then verify alignment in later reports. Record the service owner, purpose, domains used, selectors, sending IP ranges, and renewal or review date. This prevents the same investigation from recurring during staff changes or vendor migrations.
When a sender cannot be authorized, preserve relevant reports and message headers, notify the responsible security team, and review exposed credentials or compromised applications. Move DMARC enforcement gradually from monitoring to quarantine and eventually reject, while ensuring legitimate senders pass first. A strict policy is most effective when the organization understands every important mail stream.
Recommended Review Practices
- Send aggregate reports to a monitored security mailbox or DMARC analysis platform.
- Review unfamiliar IP addresses against vendor records before changing DNS.
- Track SPF, DKIM, and DMARC alignment separately for every sending service.
- Retain historical reports so unusual volume and new infrastructure stand out.
- Use domain reputation and bulk checking tools when managing multiple brands.
A disciplined DMARC review turns scattered authentication records into actionable intelligence. Start by collecting reports, mapping each sender to an owner, and documenting the decision for every unknown source. Trusted Sender Score can support that process with domain trust checks and email authentication tools, helping security teams identify unauthorized services before they damage deliverability or customer trust.