You turned on DMARC, and now a few times a day Google, Microsoft, and a handful of providers you've never heard of email you an XML file. Opened one, saw a wall of <record> tags, closed it again. This is the part of DMARC nobody walks you through, so here is how to actually read those reports and what to do with them.

What an aggregate report actually is

First, calm one fear: these reports contain no message content and no recipients. An aggregate (rua) report is a daily summary from one receiver that says, in effect, "here is the mail I saw claiming to be from your domain, grouped by sending IP, and here is how it authenticated." That's it. Counts and auth results, bucketed by source. They are how you find out who is sending as you, the legitimate senders you forgot about and the ones you never authorized.

They are also not meant to be read one message at a time. Each report is a rollup, and you get one per receiver per day, which is why doing this by hand gets old fast.

The three parts of the XML