Public explainer for weekly DMARC reports

How to read your Weekly Email Security Summary

This page explains SPF, DKIM, and DMARC, where the data in your weekly email comes from, and how Network Thinking Solutions turns DMARC aggregate reports into a readable client summary.

What this page covers

Terms, metrics, data collection, and a fake example weekly report with annotations.

Important context

DMARC reports reflect aggregate sender behavior reported by participating providers. They are not a mailbox-delivery audit.

Why this matters

A weekly summary is only useful if the reader understands what the underlying terms actually mean.

This guide translates the technical DMARC data into plain language so clients can understand what changed, what is normal, and what should be investigated.

Core authentication terms

SPF

SPF lists which mail servers are allowed to send mail for a domain.

If a message comes from an unauthorized server, SPF can fail. SPF helps stop obvious spoofing, but forwarding can break SPF even when a message is legitimate.

DKIM

DKIM adds a cryptographic signature to the message.

Receiving systems verify that signature against a public DNS record. If the signature validates, the message has not been altered in transit and the sender can be tied back to the signing domain.

DMARC

DMARC tells receiving systems how to evaluate SPF and DKIM together.

It checks alignment between the visible From domain and the domains used by SPF or DKIM, then applies your policy and generates aggregate reports that feed this weekly summary.

How NTS collects this data

Step 1

Mailbox providers send DMARC aggregate reports

Providers such as Google, Microsoft, Yahoo and others send XML aggregate reports that summarize mail claiming to be from your domains.

Step 2

NTS receives and parses those reports

Network Thinking Solutions collects those reports in the DMARC reporting pipeline, validates them, normalizes the data, and stores the weekly rollups used by this email.

Step 3

Source IPs are enriched

For Sending Sources, NTS correlates the reported source IPs with provider and network ownership data so the summary is easier to read than raw DMARC XML.

Step 4

The weekly email is generated from rollups

The email summarizes the weekly reporting window across all monitored domains for a company, using the reports received during that period.

Example weekly summary with fake data

Example only

Weekly Email Security Summary

Fictional Wealth Partners • Mar 16, 2026 - Mar 22, 2026

These example numbers are fake. They are here to show how the report is structured and what each box means.

1
Total Tracked Email Messages
12,480
Previous week: 11,920
2
DMARC Compliant
10,982
Previous week: 10,441
3
Forwarders
1,121
Forwarded mail kept trusted by DKIM.
4
Threat / Unknown
377
Previous week: 421
5
Aligned / Forwarder Safe
97.0%
Previous week: 96.3%
6
Guide link in the real email

In the actual email, this card links back to this guide so clients can see plain-language definitions and examples.

7

Daily Traffic

Daily message volume reported by DMARC aggregate reports collected by NTS.

2026-03-161,744
2026-03-171,996
2026-03-181,802
2026-03-191,933
2026-03-202,104
2026-03-211,566
2026-03-221,335
8

Top Domains

Highest-volume monitored domains for the reporting window.

exampleinvestors.com5,644
sunrisecapitalmail.com3,228
portfolioalerts.net2,611
brandupdates.io997
9

Sending Sources

Top providers or networks inferred from the source IPs in DMARC aggregate reports.

Microsoft 3654,908
HubSpot2,121
Amazon SES1,940
Proofpoint1,417
Unknown / Investigate377

Guided callouts

1
Total Tracked Email Messages

This is the total message volume reported in DMARC aggregate reports for the selected week across the monitored domains in the company.

2
DMARC Compliant

This count reflects messages reported as passing DMARC alignment. It is the cleanest signal of mail that matched the domain's authentication policy.

3
Forwarders

These are legitimate messages that were relayed through another mail server. SPF can stop matching after that handoff, but DKIM can keep the message trusted.

4
Threat / Unknown

This bucket highlights suspicious or failing traffic that did not align through SPF or DKIM and should be reviewed in the dashboard.

5
Aligned / Forwarder Safe

This percentage combines DMARC-passing traffic with safely forwarded traffic to show how much of the total volume was trusted during the week.

6
Report Guide Link

The live email includes this card so recipients can open this public explainer page without signing in.

7
Daily Traffic

Daily Traffic comes from the DMARC aggregate reports NTS collected and rolled up by day for the monitored domains in this company.

8
Top Domains

Top Domains shows which monitored domains generated the most reported message volume during the week so you can see where the activity is concentrated.

9
Sending Sources

Sending Sources are inferred from the source IPs in DMARC aggregate reports. They are useful for trend analysis, but they are not exact mailbox-delivery counts.

Important limitations to understand

DMARC aggregate reports are summaries provided by participating receivers. They are extremely useful, but they are not the same thing as exact mailbox delivery telemetry.

That means Daily Traffic, Top Domains, and Sending Sources should be treated as DMARC-reported activity. They help you spot trends, major shifts, suspicious sources, and the relative importance of different mail streams.

If something in the weekly summary looks unusual, NTS can use the dashboard and the raw DMARC reporting data to investigate the underlying senders, domains, and infrastructure.

Need direct help?

Talk to Network Thinking Solutions

We help organizations secure Microsoft 365 and Google Workspace environments, investigate DMARC issues, and improve email delivery and protection.