Skip to main content

Valimail Enforce: Domains Report

The Domains report provides a domain‑level view of how email claiming to be from your organization is authenticated, enforced, and handled by receivers. It helps you understand which domains are actively sending mail, how DMARC enforcement is applied, and where risk or misconfiguration may exist.

This report is especially useful for:

  • Identifying which domains are protected by DMARC enforcement

  • Detecting suspicious or unauthorized sending domains

  • Understanding where mail is allowed, quarantined, or rejected

  • Monitoring SPF and DKIM authentication performance over time

How to Access the Domains Report

  1. Log in to Valimail Enforce.

  2. Navigate to Reports in the left‑hand menu.

  3. Scroll down to the Standard Reports section and click on the Domains report.

Report Filters and Controls

report filters

The filters at the top of the report let you customize the data being displayed, using the following controls:

  • Domains: Filter the report to one or more specific domains.

  • Countries: Filter email activity by the country of origin.

  • Senders: Narrow the report to messages from a specific sender or sending service.

  • Date Received: Select the reporting period (up to 6 months).

  • Abbreviated Numbers: Display large values in a shortened format (e.g., 1,500 becomes 1.5K).

  • Download CSV: The exported file contains the same data currently displayed, including any filters that have been applied.

Understanding the Domains Table

Each row represents a domain observed sending mail during the selected time range. A Grand Total row summarizes activity across all domains.

example of a domains report

Columns Explained

  • Domain: The parent or organizational domain.

  • Total Emails: The total number of messages observed from this domain during the selected period.

  • Suspicious Emails: Messages that appear potentially unauthorized based on authentication signals and Valimail analysis.

  • Allowed Through - No Enforcement: Percentage of messages that passed DMARC while a policy is not enforced (p=none).

  • Allowed Through - Policy Override: Messages allowed due to an override (for example, a trusted exception, local rule, or filter).

  • Allowed Through - With Enforcement: Messages that passed DMARC authentication while the domain was under enforcement (quarantine or reject).

  • Quarantined: Percentage of messages that receivers quarantined due to DMARC failure.

  • Rejected: Percentage of messages that receivers rejected outright due to DMARC failure.

  • DMARC Pass Rate: The percentage of messages that passed DMARC (either via SPF or DKIM alignment).

  • SPF Pass Rate: Percentage of messages that passed SPF with identifier alignment.

  • DKIM Pass Rate: Percentage of messages that passed DKIM with identifier alignment.

  • Views: This column provides additional reporting options. Select the menu (⋯) to access the Senders, Countries, Daily, or Authentication Report.

Common Use Cases

Validate DMARC Enforcement Coverage

  • Quickly confirm which domains are fully enforced versus still allowing mail without enforcement.

Identify Shadow or Legacy Domains

  • Spot domains with low volume or unexpected activity that may no longer be needed or properly configured.

Investigate Suspicious Activity

  • Use the Suspicious Emails column to prioritize domains that may be abused for spoofing or phishing.

Monitor Authentication Health

  • Track SPF and DKIM pass rates to detect configuration drift or sender changes.

Did this answer your question?