DIAGNOSTIC PLAYBOOK
DMARC reports stopped arriving: separate delay from breakage
Missing DMARC reports can result from delivery delays, changed reporting configuration or a lack of reportable traffic. The absence of a report does not by itself mean authentication failed.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Check the last received report's coverage period and sender rather than its mailbox arrival time alone.
- Resolve the live rua policy and verify that the destination mailbox or service can receive reports.
- Compare recent sending volume and reporting organizations, then inspect delivery or parsing errors at the collector.
What this looks like
ILLUSTRATIVE EXAMPLE
A domain normally receives one daily report, but the sender had no traffic to that reporting provider on the next day. An empty dashboard may reflect coverage, not an outage.
A mistake to avoid
Receivers do not all send reports on the same schedule, and not all receivers report. Avoid declaring recovery from a single incoming file.
Keep the result in context
DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.