DIAGNOSTIC PLAYBOOK
Duplicate DMARC reports: avoid counting traffic twice
Aggregate reports can be resent or ingested more than once. Deduplicating reports by their identity and coverage prevents an ingestion issue from looking like a sudden traffic spike.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Compare reporting organization, report identifier, policy domain and time interval for repeated files.
- Check whether compressed and uncompressed copies or mailbox retries entered the pipeline twice.
- Recompute affected totals after deduplication and retain the original files for an audit trail.
What this looks like
ILLUSTRATIVE EXAMPLE
A collector imports both an attachment and a retried copy of the same report. The dashboard doubles the message count even though the sender's volume did not change.
A mistake to avoid
Do not deduplicate only by date or source IP. Different valid reports can cover the same period or contain the same sending source.
Keep the result in context
DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.