DIAGNOSTIC PLAYBOOK

DMARC reports stopped arriving: separate delay from breakage

Missing DMARC reports can result from delivery delays, changed reporting configuration or a lack of reportable traffic. The absence of a report does not by itself mean authentication failed.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Check the last received report's coverage period and sender rather than its mailbox arrival time alone.
  2. Resolve the live rua policy and verify that the destination mailbox or service can receive reports.
  3. Compare recent sending volume and reporting organizations, then inspect delivery or parsing errors at the collector.

What this looks like

ILLUSTRATIVE EXAMPLE

A domain normally receives one daily report, but the sender had no traffic to that reporting provider on the next day. An empty dashboard may reflect coverage, not an outage.

A mistake to avoid

Receivers do not all send reports on the same schedule, and not all receivers report. Avoid declaring recovery from a single incoming file.

Keep the result in context

DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.