DMARCmetric

Sending sources, grouped by provider

Updated 2026-07-08 · Product Guide

DMARC reports identify senders by IP address, and IP addresses are a terrible way to think about your email. What you actually want to know is "does Microsoft 365 pass?" and "what is this thing calling itself my domain from a datacentre I've never heard of?". The Sending sources table answers in those terms: every source in the reporting window, grouped by the provider that actually sent it.

What the table shows

Each row at the top level is a provider group — Microsoft 365, Postmark, Google and so on, with anything unrecognised gathered under Unknown. Groups are sorted by message volume, and each group row carries:

The pill summarises every source in the group:

PillMeaning
passEvery source in the group passes DMARC.
fail · p=noneNo source in the group aligns — delivered under a monitoring policy, but nothing here authenticates.
mixedSome sources pass and some fail — usually a half-configured provider. Expand to see which.
would rejectAt least one source in the group is a threat: mail failing both SPF and DKIM, the signature of spoofing. Under p=reject it would be refused.

A group containing a threat is flagged as a whole — one spoofed source is enough to turn its group would reject, so it can't hide behind passing neighbours.

Expanding a group

Click a group row (or focus it and press Enter) to open its individual sources. Each per-source row shows the From domain, the sending IP, the country it resolves to (flag and name), the message count, and three verdicts: SPF and DKIM alignment tags (✓ aligned or ✕ fail) plus an overall DMARC verdict — pass, fail · p=none, or would reject for threat sources.

The SPF and DKIM columns are alignment results, not bare authentication — a mechanism can pass and still fail here if the domain it authenticated doesn't match your From domain. That distinction trips almost everyone once; DMARC alignment explained covers it properly.

Two small behaviours make the table pleasant to live in: if there is only one provider, it opens already expanded; and the groups you have expanded stay open when you switch reporting windows or the data refreshes, so investigating a source doesn't reset your place.

How provider detection works

Naming a provider from a DMARC report is an inference, and we make it in three tiers, most trustworthy first:

  1. Authentication fingerprints. The report itself carries the DKIM signing domains and selectors and the SPF domain that were evaluated. Many providers leave an unmistakable signature there — Postmark's bounce domains and selectors, amazonses.com for Amazon SES, sendgrid.net for SendGrid. Because the report already authenticated these domains, this is the strongest evidence.
  2. Known IP ranges. When a source's authentication is fully aligned to your domain (so there's no provider tell in tier 1), we match its IP against a curated table of provider ranges — Google, Microsoft 365, Postmark, SendGrid, Amazon SES and others.
  3. Reverse DNS. As a last resort we look up the IP's PTR hostname and match it against known provider hostnames.

Providers recognised today include Microsoft 365, Google, Postmark, Amazon SES, SendGrid, Mailgun, Mailchimp, SparkPost, Kinsta, Zoho, Mimecast and Salesforce — and the list grows as we see more traffic. Anything that matches no tier lands in Unknown. That is honesty, not failure: an Unknown group that passes DMARC is usually just a smaller or self-hosted sender we haven't fingerprinted yet, while an Unknown group flagged would reject is exactly the thing DMARC exists to catch.

Reading it in practice

The grouping turns the table into a to-do list. "Microsoft 365 — pass" needs nothing. "Mailchimp — mixed" means one campaign setup is missing DKIM: expand it and the failing source is right there with its IP and From domain. "Unknown — would reject" from a country you don't operate in is spoofing; your DMARC policy is the fix, not that sender.

The count pill above the table ("9 sources · 3 providers") gives you the scale at a glance, and the whole view is scoped to the reporting window like everything else — see Understanding your dashboard for the full tour, including where the country data comes from.

Still stuck?

We answer every message — usually within one business day.

Email [email protected]