DMARCmetric

Understanding your dashboard

Updated 2026-07-16 · Getting Started

Once your first reports arrive, the dashboard is where you'll spend your time. This is a tour of every screen and — most importantly — a plain-English key to the verdict tags. Everything described here is live in the product; if you don't have data yet, you can explore the domain detail view with sample data in the demo — no account needed.

The all-domains overview

The dashboard opens on the overview: every domain in your workspace on one screen. Across the top:

Below sits a card per domain: its Verified or Pending badge, a compliance ring showing the percentage of mail passing DMARC, message count, threat count and when the last report arrived. Cards with active threats are flagged visually. Click any card to open that domain's detail view.

The reporting window selector in the top bar — Last 7 days, Last 30 days, Last 90 days or Last 12 months — drives both this screen and the detail view. 90-day and 12-month windows are available on Starter and above; Free includes 30 days — see pricing.

The domain detail view

The detail view answers one question: is this domain's mail authenticating, and if not, what's failing? Top to bottom:

From the top bar you can also switch domains, add another domain, open the domain's settings (DNS record, verify, remove) and export the current view.

Sending sources, grouped by provider

The Sending sources table is the heart of the dashboard. Instead of a wall of anonymous IP addresses, traffic is grouped by the provider that actually sent it — Microsoft 365, Postmark and so on, with anything unrecognised under Unknown. Each group row shows the provider, how many distinct sources it spans, total messages and a single rolled-up verdict pill. Click a group to expand its individual sources: the From domain, sending IP, country, message count, and per-source SPF, DKIM and DMARC verdicts.

This grouping is what makes action obvious. One glance tells you "Microsoft 365 passes, the CRM fails" — which is a to-do list, not a data dump. Sending sources and ESP grouping goes deeper on how providers are detected and what to do when sources appear under Unknown.

What each verdict means

The table uses a small set of tags, and they're worth learning precisely.

Group pills (one per provider, summarising all its sources):

TagMeaning
passEvery source in the group passes DMARC — at least one of SPF or DKIM is aligned.
fail · p=noneNo source in the group aligns. Under a monitoring (p=none) policy this mail is still delivered — the tag is a reminder that nothing is being blocked yet.
mixedSome of the group's sources pass and some fail — typically a provider that is half-configured. Expand it to see which.
would rejectAt least one source in the group is a threat — mail failing both SPF and DKIM, the signature of spoofing. "Would reject" means exactly that: under p=reject this mail would be refused.

Per-source columns, once a group is expanded:

LED colours carry the same story at a glance: aqua for pass, amber for mixed or failing groups, red for threats — the same red used on threat rows and threat countries.

Countries, the policy advisor and export

Three more cards round out the view:

The dashboard aggregates thousands of XML reports into these views; if you want to understand the raw material underneath, read How to read a DMARC report.

Still stuck?

We answer every message — usually within one business day.

Email [email protected]