DMARC Engine
Home/Documentation/Reports and exports
Documentation

Reports and exports

A complete walkthrough of the DMARC Engine Reports page: scheduling automated reports, reading the Domain Compliance Matrix, building an executive summary and PDF, uploading raw report files, and exporting your data as CSV or JSON.

22 June 2026 · 13 min read

Once your domains are monitored and your aggregate data is flowing, the next job is turning that data into something other people can read: a scheduled summary that lands in a colleague's inbox every Monday, a one-page compliance snapshot for a board pack, or a raw export your security team can pull into their own tooling. The Reports page is where all of that happens. It takes the same authentication and aggregate data you investigate on the Analytics and Hosted DMARC pages and packages it for distribution: as scheduled emails, as an executive PDF, or as a downloadable file.

This guide walks the Reports page top to bottom, tab by tab, naming every button and field so you can follow along click by click. If you have not yet added domains or started receiving reports, do Adding your first domain and Hosted DMARC first, because reports with no underlying data are empty. For reading the underlying aggregate data yourself, see Aggregate report analysis; this page is about exporting and sharing it rather than investigating it.

Opening the Reports page

In the dashboard, open Reports from the left-hand navigation. The page lives at https://app.dmarcengine.com/reports. Beneath the page heading is a tab bar with four tabs:

  • Scheduled Reports: automated reports that run on a recurring schedule and email themselves to a list of recipients. This is also where you upload a raw report file by hand.
  • Compliance: the Domain Compliance Matrix, a live grid scoring every domain across all five authentication mechanisms, with prioritised recommendations underneath.
  • Executive Summary: a high-level, presentation-ready view of your whole estate, with headline stat cards, a trend chart and a one-click PDF export.
  • Export: raw data export as a CSV or JSON file, scoped by date range and domain.

To the right of the tab bar sits the Create Report button, which opens the report builder modal. It does the same thing as the create action inside the Scheduled Reports tab, but it is available from anywhere on the page so you can start a new scheduled report without first switching tabs.

The sections below take each tab in turn. If you are setting up for the first time, the natural order is to check the Compliance matrix to see where you stand, glance at the Executive Summary to understand the headline picture, then create a Scheduled Report so that picture arrives automatically from then on.

Scheduled Reports

The Scheduled Reports tab is the heart of the page. It lists every recurring report you have configured and lets you create, edit and delete them, as well as upload a raw report file directly.

Uploading a report by hand

At the top of the tab is an Upload Report control. It accepts a single DMARC aggregate report file in either uncompressed .xml form or gzip-compressed .xml.gz form, which is the format mailbox providers attach to the reports they send. Most of the time you will never need this, because when you publish a DMARC record through DMARC Engine the hosted rua address ingests reports automatically and you never touch a file. Upload Report exists for the cases where automatic ingestion is not in play:

  • You received a report at your own mailbox (because the rua points somewhere other than the hosted address) and want to pull it into the platform.
  • You are backfilling historical reports that predate your account.
  • A receiver sent a report out of band and you want it counted.

Select the file and the platform parses it, matches it to the right domain by the policy published in the report, and folds its rows into the same aggregate views you see elsewhere. If you only want to inspect a single file once without storing it, the free DMARC report analyzer parses an uploaded report in your browser instead; use Upload Report here when you want the data to become part of your account's history.

The scheduled reports table

Below the upload control is a table listing every report you have scheduled. Each row is one report, with these columns:

  • Report Name: the label you gave it, so you can tell your "Weekly compliance digest" apart from your "Monthly board summary" at a glance.
  • Type: which kind of report this is, one of Aggregate, Compliance or Executive Summary (described under the modal below).
  • Frequency: how often it runs, one of Daily, Weekly or Monthly.
  • Recipients: the email addresses the finished report is sent to.
  • Next Run: the date and time the report is next scheduled to generate and send. Use this to confirm a new report is actually queued rather than silently misconfigured.
  • Status: whether the schedule is currently active.
  • Edit / Delete: the per-row actions. Edit reopens the builder modal pre-filled with this report's settings; Delete removes the schedule. Deleting a schedule stops future runs; it does not retract reports already sent.

If you have not created any reports yet, the table is empty and your starting point is either the Create Report button in the page header or the create action on this tab. Both open the same modal.

The Create / Edit Report modal

Creating a new report and editing an existing one use the same modal, so learning it once covers both. The fields are:

  • Report Name: a free-text label. Make it descriptive, because this is what appears in the table and in the subject line context of the delivered email. "Q3 finance domains, weekly" tells you far more in six months than "Report 1".
  • Report Type: a choice of three, and this is the most important field because it determines what the recipient actually receives:
  • Aggregate: the detailed, source-level view, the same data covered in Aggregate report analysis. This is for technical recipients who want to see which sources are sending and how each authenticates. Choose this for your own deliverability or security team.
  • Compliance: a snapshot of the Domain Compliance Matrix, scoring each selected domain across DMARC, SPF, DKIM, MTA-STS and BIMI. This is for someone tracking progress towards full coverage who wants a scorecard rather than raw source data.
  • Executive Summary: the high-level, jargon-light view with headline numbers and trends. Choose this for managers, clients and anyone who needs the picture without the plumbing.
  • Frequency: how often the report runs, one of Daily, Weekly or Monthly. Match the cadence to the audience: a deliverability engineer mid-rollout may want Daily; a board pack only needs Monthly. Each run covers the period since the previous run, so a weekly report summarises the week.
  • Domains: a list of checkboxes, one per domain on your account. Tick the domains this report should cover. You can scope a report to a single critical domain, to a logical group (all your finance domains, say), or to everything. Different audiences usually want different scopes, which is why scoping lives on the report rather than being global.
  • Recipients: a comma-separated list of email addresses the finished report is sent to. Separate multiple addresses with commas, for example ciso@example.com, deliverability@example.com. Recipients do not need to be users of DMARC Engine; the report is emailed to them, so anyone with an inbox can receive it. This is the simplest way to keep a stakeholder informed without giving them a dashboard login.

Save the modal and the new report appears in the table with its Next Run populated. To change anything later, use Edit on its row; to stop it, use Delete.

A common and effective setup is three standing reports: a Daily Aggregate to your own team while you are actively fixing sources, a Weekly Compliance to whoever owns the rollout, and a Monthly Executive Summary to leadership. The daily one can be deleted once you reach enforcement and things are stable.

Compliance

The Compliance tab answers one question across your whole estate at once: how complete is each domain's authentication setup, and what should I fix next. It has two parts, the matrix and the recommendations.

The Domain Compliance Matrix

The Domain Compliance Matrix is a grid with one row per domain. Each row scores that domain across five authentication mechanisms plus an overall figure:

  • Domain: the domain name.
  • DMARC, SPF, DKIM, MTA-STS and BIMI: one cell per mechanism, showing whether that mechanism is correctly configured for the domain. These map directly to the five hosted products: Hosted DMARC, Hosted SPF, Hosted DKIM, Hosted MTA-STS and Hosted BIMI.
  • Score %: an overall compliance percentage for the domain, rolling up the five mechanism cells into a single number.

The matrix is colour-coded so you can read it at a glance without inspecting individual numbers:

  • Green marks a score of 80% or above: the domain is in good shape.
  • Amber marks a score from 50% up to 80%: partially configured, with meaningful gaps remaining.
  • Red marks a score below 50%: largely unprotected, and the place to start.

Sort or scan by Score % and work the red rows first, then the amber. A red domain is one an attacker could most easily spoof, and the matrix is deliberately blunt about it so a single glance tells you where the exposure is. Green does not mean "finished" in the sense of enforcement: a domain can score well on configuration while its DMARC policy is still p=none. The matrix measures whether the mechanisms exist and are valid, which is the necessary groundwork before you tighten policy. For the policy journey itself, see The enforcement journey.

To verify any single cell independently of the dashboard, the free checkers confirm what is published in public DNS right now: DMARC checker, SPF checker, DKIM checker, MTA-STS checker and BIMI checker. They are a useful cross-check when a cell shows a gap and you want to see exactly what a receiver sees.

Recommendations

Below the matrix is a Recommendations list: specific, prioritised actions to raise your scores. Each recommendation carries a Priority badge so you tackle them in the order that reduces risk fastest:

  • Critical: a serious gap that leaves a domain exposed or actively failing, for example a domain with no DMARC record at all, or an SPF record over the ten-lookup limit. Do these first.
  • High: an important gap that is not an immediate emergency, such as a policy still at p=none on a domain that is otherwise ready to enforce, or missing DKIM on an active sending source.
  • Medium: a worthwhile improvement that adds resilience or completeness, such as adding MTA-STS or BIMI once the core three are in place.

Work the list from Critical down. Because the recommendations are generated from your live data and the matrix scores, clearing them is the most direct route to moving your red and amber rows towards green. For background on why the ten-lookup limit and policy strength matter, see Understanding your DMARC record and Hosted SPF.

Executive Summary

The Executive Summary tab is the view you show people who do not live in the dashboard. It strips the detail down to the numbers and trends that tell a story, and it produces a polished PDF you can drop straight into a report.

The stat cards

At the top are four headline stat cards, each a single big number with a label:

  • Total Domains: how many domains are on your account and covered by this summary.
  • DMARC Compliance: the overall percentage of your estate that is DMARC compliant, your single most important headline figure.
  • Service Coverage: how broadly the authentication mechanisms are deployed across your domains, a measure of completeness rather than of any one domain.
  • Threats Blocked: the volume of spoofed or failing mail that your policies have caused to be quarantined or rejected. This is the number that makes the business case: it is the spoofing that did not reach anyone because your enforcement was in place.

The supporting views

Below the cards, the tab fills in the detail behind those headlines:

  • Messages Analysed: the total volume of mail evaluated across the period, giving the stat cards their scale. A 99% compliance figure means something very different over ten thousand messages than over ten.
  • 90-Day Compliance Trend: a chart tracking your compliance over the last ninety days. This is the single most persuasive view for a non-technical audience, because it shows direction. A line climbing from red towards green tells the rollout story better than any single number.
  • Top Issues: the most significant problems currently affecting your estate, surfaced so a reader sees not just where you are but what is holding you back. This mirrors the Critical and High recommendations from the Compliance tab in plain language.
  • Domain Scores: per-domain gauges visualising each domain's score, so a leadership reader can see at a glance which domains are healthy and which need attention, without reading the full matrix.

Downloading the Executive PDF

To turn this view into a shareable document, use the Download Executive PDF control. It asks for the window the PDF should cover:

  • Start Date and End Date: the reporting period the PDF summarises. Pick the range that matches your audience, a calendar month for a monthly board pack, a quarter for a quarterly review.
  • Download PDF Report: generates the PDF for that range and downloads it to your device.

The resulting PDF is a self-contained, presentation-ready file: the same stat cards, trend and scores rendered for print and email. It is the artefact to attach to a board pack or send to a client, and because you set the date range each time, you can produce a clean document for any period on demand. If you would rather this arrive automatically every month, create a Scheduled Report with Report Type set to Executive Summary instead of generating the PDF by hand each time.

Export

The Export tab is for when a person or a system needs the underlying data itself, not a formatted summary. It produces a downloadable file scoped exactly how you want it. The controls are:

  • Export Format: choose CSV or JSON.
  • CSV is the right choice for spreadsheets and analysts. It opens directly in Excel, Numbers or Google Sheets, and is ideal for pivot tables, filtering and ad-hoc analysis.
  • JSON is the right choice for engineers and tooling. It preserves structure and nesting, and is the format to use when you are feeding the data into a SIEM, a script, a data warehouse or any system that consumes the export programmatically.
  • Start Date and End Date: the date range the export covers. Only data within this window is included, so you can pull a single month, a quarter or a full year as needed. Keep the window tight if you only need recent data; a narrower range produces a smaller, faster file.
  • Domain: a dropdown to scope the export to one domain, or to all of them. Choose a single domain when you are investigating or reporting on it specifically, or export everything for an estate-wide pull.
  • Generate Export: builds the file from your chosen format, date range and domain, and downloads it.

Use the Export tab whenever the destination is another tool rather than a human reading a summary: handing raw aggregate data to a security team, archiving a period for compliance, or loading historical data into your own analytics. If you need exports on a recurring, automated basis rather than ad hoc, the API reference describes programmatic access so a script can pull the same data on a schedule without anyone clicking Generate Export.

CSV and JSON contain the same underlying data; the difference is shape, not substance. Pick CSV when a human will open the file, JSON when a machine will parse it. If in doubt, export both once and see which your downstream tool prefers.

Choosing the right output

The Reports page deliberately offers several ways to get the same data out, because different audiences need different things. A quick guide to which to reach for:

  • A colleague who wants the picture in their inbox every week, with no login: create a Scheduled Report, pick the Report Type that matches them, and add their address to Recipients.
  • A board pack or client deliverable for a specific period: use Download Executive PDF on the Executive Summary tab, set the Start Date and End Date, and attach the file.
  • A live scorecard of where every domain stands and what to fix next: read the Domain Compliance Matrix and Recommendations on the Compliance tab directly in the dashboard.
  • Raw data for another tool, a security team or an archive: use the Export tab, choose CSV or JSON, set the range and domain, and Generate Export.
  • A one-off file you received outside the platform that you want counted: use Upload Report on the Scheduled Reports tab.

Where to go next

Reports are the output side of the platform; the input side is the data you have been collecting all along. To understand what feeds these reports, read Aggregate report analysis and Understanding your DMARC record. To be told the moment a compliance score drops rather than waiting for the next scheduled report, set up Setting up alerts. To pull the same data programmatically on your own schedule, see the API reference. And to bring more of your estate up to the green end of the compliance matrix in the first place, start with Hosted DMARC and follow The enforcement journey.

Share

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.