The silent failure
A DMARC record carrying rua=mailto:dmarc@analytics-vendor.example looks complete. Yet not a single report arrives for months, and nobody notices — because a report that fails to arrive produces no error. You simply keep waiting for data that never comes.
The reason is in RFC 7489 §7.1. When a report destination points at a different organizational domain than the sender's, that external domain has to consent to receiving them. Otherwise any domain owner could flood someone else's mailbox with reports simply by naming it in their own record. The consent is a TXT record on the destination side:
Read it as: "The domain analytics-vendor.example agrees to receive DMARC reports about example.com." Without this record, conforming receivers — Google and Microsoft among them — stop delivering.
What AnalyzeMy.Email checks
- Detection of external destinations — the comparison is on the organizational domain, not the full name.
rua=mailto:dmarc@reports.example.comfor senderexample.comis internal and needs nothing. - A real DNS lookup of
<sender-domain>._report._dmarc.<destination-domain>— not merely a format check of the rua value. - Content validation for
v=DMARC1. A record that exists but says the wrong thing does not count as authorization. - Deduplicated per destination domain — rua and ruf pointing at the same domain need only one record and are evaluated together.
- Number of destinations — more than two rua or ruf addresses is flagged, because many receivers only deliver to the first one or two.
The outcome has three values: authorized, not authorized (severe — no reports will arrive) or a DNS error while looking (a low finding, since it may simply be a timeout).
When this affects you
Practically always when a DMARC analytics service is involved. Such vendors issue an address in their own domain — exactly the case §7.1 governs. Reputable services create the record automatically once you register the domain with them; copy the address out of the documentation without registering anywhere and you get nothing.
The second common case is the corporate group: rua for every subsidiary domain pointing centrally at dmarc@holding.example. That is external too as soon as the organizational domain differs — each individual subsidiary domain needs its own authorization record on the holding company's side.
Recommendations
- Actually verify that reports arrive after setting this up. The first delivery typically comes after 24 to 48 hours.
- Add a second, internal destination — an address in your own domain needs no authorization and is the reliable fallback.
- At most two destinations per report type, or some receivers' limits kick in.
- Use
rufsparingly: forensic reports contain parts of real messages. Many receivers do not send them anyway, and they are awkward under data protection law.