Back to all articles
Technical Guide

Detecting Email Spoofing with DMARC Reports

NT
The Network Tools TeamSecurity Research
Published
Read Time1 min

Email spoofing is the digital equivalent of a forged signature—attackers send messages that appear to come from a trusted domain, hoping recipients will click a malicious link or hand over credentials. The most reliable way to spot these imposters is by digging into DMARC (Domain‑Based Message Authentication, Reporting & Conformance) reports. In this guide we’ll break down how DMARC works, what to look for in its reports, and how to turn that data into a proactive anti‑spoofing strategy.

What is Email Spoofing and Why It Matters

  • Spoofing 101 – Think of a fake ID at a club door. The name looks right, but the photo is wrong. In email, the “From” address is the name, while the underlying authentication (SPF/DKIM) is the photo.
  • Business impact – A single successful spoof can lead to credential theft, ransomware infection, or brand reputation damage. According to the 2023 Verizon Data Breach Investigations Report, 30 % of phishing attacks use spoofed domains.

DMARC in a Nutshell

Component Purpose Example
SPF (Sender Policy Framework) Lists which IPs are allowed to send mail for a domain. v=spf1 ip4:192.0.2.0/24 -all
DKIM (DomainKeys Identified Mail) Adds a cryptographic signature to the message header. DKIM-Signature: a=rsa‑sha256; d=example.com; …
DMARC Tells receiving servers what to do when SPF/DKIM fail and generates reports. v=DMARC1; p=reject; rua=mailto:[email protected]

When a receiving server evaluates an inbound message, it checks SPF and DKIM against the “From” domain. DMARC then decides whether to accept, quarantine, or reject the message and sends a report back to the domain owner.

How DMARC Reports Are Structured

DMARC generates two types of reports:

  1. Aggregate reports (rua) – XML files summarizing authentication results for thousands of messages over a 24‑hour period.
  2. Forensic reports (ruf) – Detailed logs for each individual message that failed DMARC.

The aggregate report is the goldmine for detecting spoofing trends. It contains fields such as:

  • source_ip – IP address that sent the message.
  • count – Number of messages from that IP.
  • disposition – What the receiver did (none, quarantine, reject).
  • dkim / spf – Pass/Fail status.

Spotting Spoofing Indicators in Aggregate Reports

1. Unexpected Source IPs

If you see a high count from an IP that isn’t in your SPF record, that’s a red flag.

<record>
  <row>
    <source_ip>203.0.113.45</source_ip>
    <count>152</count>
    <policy_evaluated>
      <disposition>reject</disposition>
      <dkim>fail</dkim>
      <spf>fail</spf>
    </policy_evaluated>
  </row>
</record>

2. “none” Disposition with High Failure Rates

A none disposition means the receiver didn’t enforce a policy. If you notice many dkim=fail or spf=fail entries under none, it suggests attackers are testing the waters.

3. Sudden Spikes in Volume

A spike from a single IP or a new country can indicate a coordinated spoofing campaign. Plotting count over time (e.g., in a spreadsheet) makes these spikes obvious.

4. Misaligned DKIM Signatures

When the dkim domain (d= tag) doesn’t match the From domain, DMARC will fail. Look for records where dkim=pass but the signing domain is different.

Real‑World Example: The “Invoice Scam”

Scenario – A mid‑size SaaS company receives a flood of “Invoice Attached” emails that appear to come from [email protected].

What the DMARC report showed

  • source_ip: 198.51.100.77 (not in Acme’s SPF).
  • count: 1,240 messages in a single day.
  • disposition: reject (good, because the policy was set to reject).
  • dkim: fail for every message.

Action taken

  1. Added the offending IP to a blocklist on the mail gateway.
  2. Tightened SPF to include only authorized sending services.
  3. Updated DMARC policy from p=none to p=reject.

Within 48 hours, the volume dropped to zero, confirming the spoofing source was neutralized.

Turning DMARC Data into an Anti‑Spoofing Playbook

  1. Set a baseline – Run DMARC with p=none for a week and collect reports.
  2. Identify legitimate senders – Whitelist IPs and services that consistently pass SPF/DKIM.
  3. Raise the policy – Move to p=quarantine then p=reject once you’re confident the baseline is clean.
  4. Automate parsing – Use a script or a SaaS dashboard to convert XML into readable tables.

Tools to Simplify DMARC Analysis

  • The Network Tools – Our platform offers a DMARC report parser that visualizes source IPs, failure rates, and geographic distribution in a single dashboard.
  • Open‑source options: opendmarc, dmarcian, postmark/dmarc-report-parser.

Step‑by‑Step: Using The Network Tools for DMARC Diagnostics

  1. Create a free account on The Network Tools.
  2. Navigate to “DMARC Analyzer” and paste your rua XML file (or provide the mailbox URL).
  3. The tool automatically extracts:
    • Top failing IPs
    • SPF/DKIM pass‑fail ratios
    • Trend graphs for daily volume
  4. Export the findings to CSV for deeper analysis or share with your security team.

Best Practices for Ongoing Spoofing Detection

Practice Why It Helps
Publish a strict DMARC policy (p=reject) Forces attackers to fail outright.
Rotate DKIM keys every 6‑12 months Reduces the window for key compromise.
Monitor sub‑domain alignment Attackers often target mail.sales.example.com.
Enable BIMI (Brand Indicators for Message Identification) Adds a visual logo, making spoofed messages easier to spot for recipients.
Integrate DMARC alerts with SIEM Real‑time alerts when a new IP appears.

Frequently Asked Questions

Q: How often should I review DMARC reports?
A: At a minimum weekly during the onboarding phase, then monthly once the policy stabilizes.

Q: Do forensic reports (ruf) add value?
A: Yes, they give per‑message details that help trace the exact payload that triggered a failure.

Q: Can I use DMARC to protect sub‑domains?
A: Absolutely. Set sp=reject to apply the same policy to all sub‑domains.

Q: What if a legitimate third‑party service fails SPF?
A: Add the service’s sending IPs to your SPF record or configure a dedicated sub‑domain with its own DKIM key.

Wrap‑Up

Detecting email spoofing with DMARC reports is less about chasing a single bad email and more about spotting patterns that reveal an attacker’s playbook. By parsing aggregate XML, flagging unknown source IPs, and progressively tightening your DMARC policy, you turn a passive reporting mechanism into an active defense layer.

Ready to turn raw DMARC data into clear, actionable insights? Give The Network Tools a spin—our DMARC analyzer does the heavy lifting so you can focus on protecting your brand and inboxes.

You might also need

Keep troubleshooting with these related free tools.