Skip to main content
email·digit

DMARC report too large to analyze: what the refusal means

If a DMARC analyser says your report is too large or cannot be read, it has refused the whole report rather than show you part of it, which is the right behaviour: a partial count presented as complete can hide the sender you most need to see. Check that the file is a complete, unedited aggregate report; if it really is that large, split its records across several files, each keeping the report’s metadata and policy sections, and analyse each part.

Why a DMARC report is untrusted input

DMARC aggregate reports are XML files, usually compressed, that mailbox providers send to the rua address in your DMARC record. They list every IP that sent mail as your domain and whether it passed. They are the evidence you want before moving your policy from p=none toward p=reject.

They also arrive from servers you do not control, and anyone can send mail to a reporting address. So a tool that reads them has to assume a file might be built to cause harm:

  • Entity expansion. XML can declare entities that expand into other entities. A few hundred bytes can expand into gigabytes in memory, the attack known as “billion laughs”. Genuine aggregate reports never contain these declarations.
  • Compression bombs. A small .gz or .zip can decompress to something enormous.
  • Sheer size. A file of millions of tiny records is valid XML and still too much work for one request.

Refuse or truncate: why it matters

Any parser needs limits. The question is what it does when it reaches one. The easy option is to stop reading and show what it has. Imagine a report with 60,000 records and a tool that stops at 50,000:

QuestionTruncated analysisWhat the full report says
Sources shownEvery source in the first 50,000 recordsPlus any that appear only in the last 10,000
Pass rateComputed from part of the mailCan be different in either direction
An unknown sender at 203.0.113.40InvisibleFailing DMARC, and the reason to wait

Nothing on the truncated screen says it is incomplete. It looks like a clean result, and a clean result is what tells you it is safe to reject failing mail. Refusing is less convenient and much safer: you know you do not have an answer, rather than holding a wrong one.

How the free analyser handles it

Email Digit’s free DMARC report analyser takes a report as pasted XML or an uploaded .xml file, with no account. Extract a .gz or .zip first. It shows each sending source, how much mail it sent and whether it passed, with a plain-English summary. The summary is computed from the report itself, not written by AI, so the same report always gets the same answer. The analyser returns the result and does not keep a copy.

Before it shows anything, it checks the file against these limits:

  • Input up to about 8 MB of XML.
  • No document type or entity declarations at all. They are refused before parsing starts, not expanded and then measured.
  • At most 50,000 records, and at most 10,000 distinct sending IPs.

The record and source limits are counted while the file is read, so an oversized report is refused early rather than after all the work. Past either limit, the whole report is refused with a reason. Real aggregate reports, even for busy domains, are usually far smaller.

What each refusal means

MessageLikely cause and what to do
“Report has more than 50,000 records: too large to analyze”A very large or merged report. Split it, or use reports covering a shorter period.
“Report covers more than 10,000 distinct source IPs”Unusual for one domain. Look at where the file came from before trusting it.
“XML document type declarations are not allowed”Not produced by a normal reporter, or edited since. Use the original attachment.
“Not a DMARC aggregate report”The wrong file: often the email around the report, or a failure (RUF) report.
“Invalid XML”Usually a paste that was cut short. Upload the .xml file instead.
“Report is too large to analyze”Over the size limit. Split it as above.

The analyser is shared by everyone who uses it, so it also has a rate limit of 10 reports a minute from one IP address, and when it is busy it asks you to try again in a moment rather than queueing you silently.

What it does not do

It reads one report at a time, the one you give it. It does not collect the reports sent to your rua address or track sources over weeks; that part is still yours. For reading the result line by line, see how to read a DMARC report, and for the sources you do not recognise, unknown IPs in your DMARC report.

Share this guideShare on XShare on LinkedIn