Email authentication
DMARC monitoring and RUA report analysis
DMARC does not end when the record is published. Aggregate reports show who sends as your domain, which sources align, and where stronger policy could disrupt legitimate mail.
A published policy still needs observation
A malformed record may leave a domain open to impersonation or disrupt legitimate delivery. RUA reports contain receiver-level aggregates, and manual interpretation becomes difficult as source count and volume grow.
Authorized sources
Classify known senders without conflating them with unknown services.
Alignment
Observe SPF and DKIM outcomes relative to the domain visible to recipients.
Policy
Track `none`, `quarantine`, `reject`, and percentage rollout before enforcement changes.
From aggregate XML to reviewable decisions
LuminaKite receives RUA through an assigned alias, normalizes aggregate data, and presents trends. The assistant supports source classification and readiness review; it does not edit DNS or guarantee every receiver will report.
Receive
Process aggregate XML while avoiding unnecessary retention of raw attachments.
Explain
Connect volume, source, disposition, and authentication outcomes.
Prioritize
Separate legitimate failures, forgotten services, and signals worth investigating.
Manual analysis versus monitoring
Unpacking a report and reading XML is useful for learning or investigating one case. Monitoring adds continuity, classification, and history. Moving to `reject` still requires owner validation and a gradual rollout.
Frequently asked questions
Does LuminaKite change my DMARC policy?
No. It analyzes evidence and may suggest a record; the customer retains control of DNS.
Do RUA reports contain email messages?
They are aggregate reports, not message bodies. They may contain source IPs and authentication domains and are protected as tenant data.
Should I move directly to p=reject?
No. Identify senders, fix alignment, and advance gradually to avoid blocking legitimate mail.
Turn DMARC reports into decisions
Centralize RUA and review alignment before tightening policy.
Start freeRelated content
Technical guide
How to analyze DMARC RUA reports without losing legitimate senders
Interpret aggregate DMARC RUA data, SPF/DKIM alignment, and disposition before moving from p=none to enforcement.
Technical guide
How to check SPF, DKIM, and DMARC correctly
Check SPF, DKIM, and DMARC syntax and alignment, understand common errors, and learn why a single pass does not guarantee protection.
Free tool
DMARC checker
Look up a domain's public DMARC record, identify policy and percentage, and understand what a spot check cannot confirm.
Domain trust
DNS and email security monitoring
Detect DNS record changes and monitor SPF, DKIM, DMARC, MX, nameserver, MTA-STS, and TLS-RPT posture across your domains.