1

Topic: Anyone that can interpret this dmark report

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release):
- Deployed with iRedMail Easy or the downloadable installer?
- Linux/BSD distribution name and version:
- Store mail accounts in which backend (LDAP/MySQL/PGSQL):
- Web server (Apache or Nginx):
- Manage mail accounts with iRedAdmin-Pro?
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====

Can anyone interpret the copied dmark report? The source IP it seems to be from Africa somewhere.
But which dkim and spf is it that fail.

<?xml version='1.0' encoding='utf-8'?><feedback><report_metadata><org_name>Mail.Ru</org_name><email>dmarc_support@corp.mail.ru</email><extra_contact_info>http://help.mail.ru/mail-help</extra_contact_info><report_id>12628499095920880451728000000</report_id><date_range><begin>1728000000</begin><end>1728086400</end></date_range></report_metadata><policy_published><domain>mxmail.pro</domain><adkim>r</adkim><aspf>r</aspf><p>reject</p><sp>reject</sp><pct>100</pct></policy_published><record><row><source_ip>41.72.2.48</source_ip><count>1</count><policy_evaluated><disposition>reject</disposition><dkim>fail</dkim><spf>fail</spf></policy_evaluated></row><identifiers><header_from>mxmail.pro</header_from></identifiers><auth_results><spf><domain>mxmail.pro</domain><scope>mfrom</scope><result>softfail</result></spf></auth_results></record></feedback>

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Anyone that can interpret this dmark report

Well, someone forged the sender, which leads to SPF fail, and the dkim is wrong aswell, you can't prevent this, just see it as information that you maildomain is abused somewhere as forged spam mail

3

Re: Anyone that can interpret this dmark report

Really not everyone has successfully done dmark report. The steps you shared are really logical to make it simpler.

4

Re: Anyone that can interpret this dmark report

This DMARC report shows that Mail.Ru received an email from 41.72.2.48 purportedly from mxmail.pro, but it failed both SPF and DKIM checks. As a result, Mail.Ru rejected the email in line with mxmail.pro's DMARC policy, which is set to reject.