To extract raw DMARC reports, authenticate your request using an API token in the X-Api-Token header. First, call the list endpoint with date filters to retrieve the specific Report ID for your domain. Then, use that ID in a second GET request to fetch the full raw payload, which includes detailed SPF/DKIM evaluation records from ISPs like Google or Microsoft. This two-step process allows you to bypass summarized digests and access the granular data needed for precise deliverability troubleshooting. For SendroAI users, while this manual API approach provides deep technical visibility, our Performance Analytics dashboard automates the ingestion of these signals, correlating them with send volume and reply rates to optimize your cold email infrastructure without requiring manual XML parsing.
Step 1: Authenticate Your DMARC API Access Token
Are you manually downloading and parsing XML files from your email provider’s dashboard, wasting hours on data entry that adds zero strategic value to your deliverability audits?
Most B2B marketers treat DMARC reports as static attachments. They download the weekly CSV or XML blob, open it in Excel, and spend their Friday afternoon highlighting rows. This is busy work. It is not auditing. It is administrative friction that delays critical insights about spoofing attempts and alignment failures.
The top 1% of technical teams bypass the manual download entirely by querying the raw XML feed programmatically.
Manual parsing takes hours and introduces human error. API authentication allows for real-time extraction of unprocessed aggregate data, enabling automated anomaly detection before a domain reputation crisis hits.
Generate Your Unique Access Token
Before you can extract any raw data, you must secure an authenticated session with your DMARC aggregator. Most providers issue a unique API token during account setup or via a dedicated developer settings panel. This token acts as your digital key, replacing username/password combinations with a more secure, scoped credential.
Locate your token in your provider’s security or integrations dashboard. If you cannot find it, check your initial onboarding email or contact support. Never share this token publicly or commit it to version control systems like GitHub without proper secret management practices.
Rotate your API tokens quarterly. Treat them like passwords. If a team member leaves or a potential breach is suspected, invalidate the old token immediately and generate a new one to prevent unauthorized access to your raw DMARC XML feeds.
| Credential Type | Security Level | Recommended Use Case |
|---|---|---|
| API Token | High | Automated scripts and CI/CD pipelines |
| Username/Password | Low | Manual dashboard access only |
| OAuth Client Secret | Very High | Third-party integration partnerships |
Step 2: Retrieve the Specific Report ID Using Date Filters
You have your API credentials ready. Now you need to find the specific report ID for the date range you are auditing. Most DMARC APIs use a list endpoint to return metadata about received reports before you can fetch the actual raw data.
This step is critical because raw XML files are often large and compressed. Fetching the full payload without a valid ID will waste bandwidth and time. You must filter by date to isolate the exact reporting window.
Filtering by Date Range
Use the from_date and to_date query parameters in your GET request. This limits the response to only the reports generated within that specific window. It prevents you from sifting through months of irrelevant data.
Most providers expect ISO 8601 format (YYYY-MM-DD). Stick to this standard to avoid parsing errors that could break your automation scripts.
- Set from_date to the start of your audit period.
- Set to_date to the end of your audit period.
- Include a limit parameter to control pagination if needed.
Illustrative Example: Retrieving reports for Google's domain between January 2nd and January 16th, 2017.
Result: The API returns a JSON object containing an array of entries. Each entry includes an 'id' field, which is the unique identifier you need for the next step.
Look closely at the response structure. You will see a list of objects. Each object represents a single aggregate report batch from an ISP like Google or Yahoo. The key field here is id or external_id.
Do not confuse the domain field with the report ID. The domain tells you who sent the report. The ID tells you how to retrieve it. Always map the correct ID to your target organization domain.
If you receive multiple IDs for the same date range, check the date_range_begin and date_range_end fields. Some ISPs split reports by day or hour. You may need to combine several IDs to get the full picture.
Once you have the ID, you are one call away from the raw XML. This method ensures you are pulling exactly what you need for your deliverability audit. For more on technical verification, see our guide on How to Send Test Messages Via SMTP: A Step-by-Step Technical Verification Guide.
Step 3: Fetch the Raw XML or JSON Payload by ID
You have your Report ID. Now you need the actual data payload.
This is where most deliverability audits stall. You don't want a summary. You want the raw XML or JSON sent by the ISP.
The API call changes slightly based on what format you need. The endpoint remains the same. Only the headers shift.
Requesting JSON vs. XML
JSON is easier to parse programmatically. Use it for automation pipelines.
XML matches the original DMARC standard structure. Use it for strict compliance auditing.
Illustrative Example: Fetching Google's raw report in JSON format using cURL
Result: curl https://api.dmarc-provider.com/reports/12345 -H 'Accept: application/json' -H 'Authorization: Bearer YOUR_TOKEN'
Notice the Accept header. This dictates the response type.
If you omit this header, some APIs default to JSON. Others return XML. Always specify it explicitly.
Your authentication token must be valid. An expired token returns a 401 error immediately.
| Format | Use Case | Parsing Difficulty |
|---|---|---|
| JSON | Automated scripts, dashboards | Low (Native support) |
| XML | Compliance checks, legacy systems | High (Requires specific parsers) |
The response time varies. Large ISPs like Google send massive files.
You might see timeouts if your script isn't optimized. Increase your read timeout to 30 seconds minimum.
Always check the Content-Type header in the response. It confirms the actual format returned, not just what you asked for.
Once you receive the payload, save it locally. Do not process it live.
Raw reports contain sensitive IP data. Store them securely.
You can now feed this data into your audit tools. Or compare it against your internal logs.
This step completes the extraction phase. You now own the truth about your email authentication status.
Understanding the Raw Record Schema for Deliverability Diagnostics
Raw DMARC XML reports are the bedrock of any serious deliverability audit. You cannot fix what you cannot see clearly. Aggregate reports summarize data, but they often hide the granular details needed to diagnose subtle authentication failures.
The raw schema provides a line-by-line breakdown of every email attempt. It captures specific IP addresses, authentication results for SPF and DKIM, and the final disposition decision made by the reporting MTA.
Decoding the Core Record Fields
When you query the API, you receive a structured object. Each record within that object represents a single message instance. Understanding these fields is critical for identifying spoofing attempts or misconfigurations.
The source_ip field is your primary forensic tool. It tells you exactly which machine sent the email. If this IP does not match your authorized sending infrastructure, you have a spoofing issue or a rogue sender.
Look closely at policy_evaluated_spf and policy_evaluated_dkim. These fields indicate the outcome of the authentication checks performed by the receiving domain. A consistent failure here signals a broken alignment strategy.
You must also monitor policy_evaluated_disposition. This reveals how the receiver handled the message. Values like none, quarantine, or reject directly impact your inbox placement rates.
Illustrative Example: A B2B cold email campaign targets enterprise clients using Google Workspace.
Result: The raw report shows policy_evaluated_disposition as 'quarantine' for 40% of messages. The source_ip matches your dedicated pool, but SPF fails due to an embedded tracking pixel redirecting through a third-party domain.
This scenario highlights why raw data beats summaries. A summary might just show a high failure rate. The raw record exposes the exact mechanism: the tracking pixel breaking SPF alignment.
For deeper context on how third-party senders affect your reputation, review DKIM and the Via Label in Gmail.
Advanced Schema Nuances for 2026 Audits
Modern DMARC implementations include additional fields that provide richer context. These fields help distinguish between technical errors and malicious intent.
- header_from: The domain in the From: header. Compare this against your authenticated domains to check for display name spoofing.
- spf_domain: The domain used for SPF evaluation. Mismatches here often indicate proxy issues.
- dkim_domain: The domain signing the DKIM signature. Null values suggest missing signatures entirely.
Integrating Raw Data into SendroAI’s Automated Sequencing Workflow
Raw DMARC XML isn’t just data. It’s your deliverability diagnostic engine. Most teams stop at the dashboard summary. That’s a mistake. You need the granular IP-level failures to fix root causes, not just symptoms.
Integrating this raw feed into your sequencing workflow changes everything. Instead of manual CSV exports, you automate the audit loop. Your system pulls the XML, parses the policy evaluation fields, and flags risky IPs before they hurt your inbox placement.
Automating the Audit Loop
The goal is zero-touch verification. You configure your API client to fetch daily or weekly aggregates. Then, you map specific XML tags to your sending infrastructure rules. If an IP fails SPF consistently, your workflow automatically pauses campaigns for that domain range.
- Parse the
policy_evaluated_spftag to identify immediate authentication failures. - Monitor
source_ipfrequency to detect sudden spikes in unauthorized sending. - Track
dispositionchanges (none to quarantine) as early warning signals. - Cross-reference
header_fromdomains against your approved sending list.
This approach aligns with modern outbound strategies. You’re not just checking boxes. You’re building a feedback mechanism that keeps your sender reputation pristine. See how The 2026 Growth Protocol: Integrating AI-Driven Outbound into the AARRR Funnel leverages similar automated loops for scale.
| XML Field | Actionable Insight |
|---|---|
policy_evaluated_dkim |
Failures indicate missing or misconfigured DKIM keys. Rotate keys immediately. |
count |
High counts from a single IP suggest volume issues or spoofing attempts. |
spf_result |
Pass/Fail status determines if the email was authenticated by the receiver. |
You must also consider technical alignment. Raw data reveals gaps between your return-path and DMARC policies. If these don’t align, even valid emails get flagged. Read Aligning Return-Path and DMARC: The Technical Mechanism for B2B Cold Email Deliverability to understand the mechanics.
Set up alerts for any disposition change to quarantine or reject. These are the first signs that ISPs are losing trust in your domain.
Don’t ignore the external sources. Google and Yahoo provide strict guidelines. Use their sender guidelines and Yahoo sender best practices as the baseline for your parsing logic. If your raw data violates these, your automation should flag it instantly.
Illustrative Example: A B2B agency receives a spike in policy_evaluated_spf failures for a new subdomain.
Result: The automated workflow pauses all outreach to that subdomain, generates a ticket for the IT team to check DNS records, and resumes only after a successful re-authentication test.
This level of control prevents catastrophic deliverability drops. You catch errors when they happen, not weeks later during a quarterly review. It turns reactive troubleshooting into proactive management.
Key Integration Rules
- Never rely solely on summary dashboards for critical decisions.
- Automate the parsing of XML tags to reduce human error.
- Link raw data failures directly to campaign pause triggers.
- Regularly validate your parser against IETF RFC standards like SPF RFC 7208 and DKIM RFC 6376.
Raw XML dumps are the only way to audit policy evaluation logic at scale. You cannot trust dashboard summaries when you are managing high-volume B2B outreach. The raw data reveals exactly how receivers like Google and Yahoo interpret your SPF and DKIM signatures.
The Authentication Header Protocol
You must pass your API token in the X-Api-Token header for every request. This is not optional. If you omit this header, the endpoint returns a 401 Unauthorized error immediately.
Use cURL or Postman to test connectivity before building your pipeline. A simple GET request confirms your credentials are valid and active.
Illustrative Example: Retrieving reports for a specific domain using date filters
Result: curl https://dmarc.postmarkapp.com/records/my/reports?from_date=2026-01-01&to_date=2026-01-31 -H 'X-Api-Token: YOUR_TOKEN'
Parsing the XML Structure
Change your Accept header to application/xml to get the raw format. This structure mirrors the IETF standard closely. You will see <Feedback> blocks containing <Report> sections.
Each report contains a <Record> array. This is where the actionable intelligence lives. You need to iterate through these records to find failures.
- Check
PolicyEvaluatedfordispositionvalues. - Analyze
SourceIPto identify unauthorized senders. - Review
SPFResultandDKIMResultfor alignment issues.
Raw XML dumps are the only way to audit policy evaluation logic at scale. You cannot trust summary dashboards when your domain reputation is on the line.
Most teams stop at the aggregate view. This leaves critical spoofing attempts invisible until a major inbox provider blocks your entire sending pool.
The Technical Gap in Aggregate Views
Aggregate reports summarize data. They hide the specific source IPs that failed authentication but slipped through due to lax policy settings.
You need the granular source_ip and spf_result fields to identify rogue senders. Without this, you are flying blind against brand impersonation.
Always request the raw XML via API rather than relying on email attachments. Automated parsing ensures you never miss a daily digest spike.
- Filter by
policy_evaluated_dispositionto find quarantine failures. - Cross-reference
source_ipwith your known sender list immediately. - Track
dkim_domainmismatches to catch third-party vendor drift.
Illustrative Example: A SaaS company notices a 15% drop in open rates overnight.
Result: Raw API analysis revealed a new affiliate partner was spoofing their domain. The dkim_result showed 'fail' while policy_evaluated_disposition was 'none'. They blocked the IP range within hours.
This level of forensic detail is impossible to get from a standard dashboard. It requires direct access to the underlying IETF standards data.
For deeper context on how these technical signals impact your overall strategy, review our guide on Aligning Return-Path and DMARC: The Technical Mechanism for B2B Cold Email Deliverability.
You should also monitor how AI inbox summaries are changing engagement metrics. See How AI Inbox Summaries Are Rewiring Email Engagement: A 2026 Deliverability and Strategy Analysis for the latest trends.
What SendroAI Does
SendroAI is a B2B cold email outreach and inside sales platform. It automates prospect research and personalized email generation through six core capabilities:
- AI Research Engine — researches each company and prospect, then writes a unique, hand-written-feeling cold email per prospect with no templates or pattern detection.
- Automated Sequencing — generates every follow-up uniquely from context and engagement, stopping instantly when a prospect replies.
- A/Z Email Testing — optimizes content, personalization, timing, and deliverability simultaneously instead of one-variable A/B tests.
- Inbox Rotation — rotates sends across verified mailboxes with warm, human-like behavior to protect domain reputation and scale volume.
- Multilingual Campaigns — creates native-sounding cold email campaigns in 50+ languages without relying on machine translation.
- Performance Analytics — delivers campaign-level analytics and mailbox-level deliverability insights focused on reply-driven outcomes.
