SPF lists which mail servers are allowed to send mail for a domain.
If a message comes from an unauthorized server, SPF can fail. SPF helps stop obvious spoofing, but forwarding can break SPF even when a message is legitimate.
This page explains SPF, DKIM, and DMARC, where the data in your weekly email comes from, and how Network Thinking Solutions turns DMARC aggregate reports into a readable client summary.
Terms, metrics, data collection, and a fake example weekly report with annotations.
DMARC reports reflect aggregate sender behavior reported by participating providers. They are not a mailbox-delivery audit.
A weekly summary is only useful if the reader understands what the underlying terms actually mean.
This guide translates the technical DMARC data into plain language so clients can understand what changed, what is normal, and what should be investigated.
SPF lists which mail servers are allowed to send mail for a domain.
If a message comes from an unauthorized server, SPF can fail. SPF helps stop obvious spoofing, but forwarding can break SPF even when a message is legitimate.
DKIM adds a cryptographic signature to the message.
Receiving systems verify that signature against a public DNS record. If the signature validates, the message has not been altered in transit and the sender can be tied back to the signing domain.
DMARC tells receiving systems how to evaluate SPF and DKIM together.
It checks alignment between the visible From domain and the domains used by SPF or DKIM, then applies your policy and generates aggregate reports that feed this weekly summary.
Providers such as Google, Microsoft, Yahoo and others send XML aggregate reports that summarize mail claiming to be from your domains.
Network Thinking Solutions collects those reports in the DMARC reporting pipeline, validates them, normalizes the data, and stores the weekly rollups used by this email.
For Sending Sources, NTS correlates the reported source IPs with provider and network ownership data so the summary is easier to read than raw DMARC XML.
The email summarizes the weekly reporting window across all monitored domains for a company, using the reports received during that period.
Fictional Wealth Partners • Mar 16, 2026 - Mar 22, 2026
These example numbers are fake. They are here to show how the report is structured and what each box means.
In the actual email, this card links back to this guide so clients can see plain-language definitions and examples.
Daily message volume reported by DMARC aggregate reports collected by NTS.
Highest-volume monitored domains for the reporting window.
Top providers or networks inferred from the source IPs in DMARC aggregate reports.
This is the total message volume reported in DMARC aggregate reports for the selected week across the monitored domains in the company.
This count reflects messages reported as passing DMARC alignment. It is the cleanest signal of mail that matched the domain's authentication policy.
These are legitimate messages that were relayed through another mail server. SPF can stop matching after that handoff, but DKIM can keep the message trusted.
This bucket highlights suspicious or failing traffic that did not align through SPF or DKIM and should be reviewed in the dashboard.
This percentage combines DMARC-passing traffic with safely forwarded traffic to show how much of the total volume was trusted during the week.
The live email includes this card so recipients can open this public explainer page without signing in.
Daily Traffic comes from the DMARC aggregate reports NTS collected and rolled up by day for the monitored domains in this company.
Top Domains shows which monitored domains generated the most reported message volume during the week so you can see where the activity is concentrated.
Sending Sources are inferred from the source IPs in DMARC aggregate reports. They are useful for trend analysis, but they are not exact mailbox-delivery counts.
DMARC aggregate reports are summaries provided by participating receivers. They are extremely useful, but they are not the same thing as exact mailbox delivery telemetry.
That means Daily Traffic, Top Domains, and Sending Sources should be treated as DMARC-reported activity. They help you spot trends, major shifts, suspicious sources, and the relative importance of different mail streams.
If something in the weekly summary looks unusual, NTS can use the dashboard and the raw DMARC reporting data to investigate the underlying senders, domains, and infrastructure.
We help organizations secure Microsoft 365 and Google Workspace environments, investigate DMARC issues, and improve email delivery and protection.