{"id":4879,"date":"2026-10-01T03:01:36","date_gmt":"2026-09-30T21:31:36","guid":{"rendered":"https:\/\/cpanelfree.com\/blog\/how-to-parse-and-analyze-dmarc-aggregate-reports-with-open-source-tools-on-linux\/"},"modified":"2026-10-01T03:01:36","modified_gmt":"2026-09-30T21:31:36","slug":"how-to-parse-and-analyze-dmarc-aggregate-reports-with-open-source-tools-on-linux","status":"publish","type":"post","link":"https:\/\/cpanelfree.com\/blog\/how-to-parse-and-analyze-dmarc-aggregate-reports-with-open-source-tools-on-linux\/","title":{"rendered":"How to Parse and Analyze DMARC Aggregate Reports with Open-Source Tools on Linux"},"content":{"rendered":"<p>Enforcing a strict <code>p=reject<\/code> DMARC policy without end-to-end visibility into legitimate email sending vectors is one of the quickest ways for infrastructure teams to accidentally drop critical transactional traffic. Major mailbox providers like Google, Microsoft, and Yahoo emit millions of compressed aggregate XML reports (RUA) daily to the URI specified in your DNS records, yet manually parsing and correlating these disparate archives creates unsustainable administrative overhead. When developing delivery setups or testing mail configurations on <a href=\"https:\/\/cpanelfree.com\">CpanelFree<\/a>, deploying an autonomous, self-hosted Linux pipeline converts raw XML archives into actionable deliverability metrics without incurring steep enterprise SaaS costs.<\/p>\n<p><!-- more --><\/p>\n<h2 style=\"color:#001b41;font-size:28px;font-weight:700;margin-top:32px\">What Is the Best Way to Parse and Analyze DMARC Reports on Linux?<\/h2>\n<div style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-left:4px solid #001b41;border-radius:4px;padding:18px 22px;margin:24px 0\">\n<p style=\"margin:0;font-size:16px;line-height:1.6;color:#333\"><strong style=\"color:#001b41\">Direct Answer:<\/strong> The most efficient open-source approach to parse DMARC aggregate reports linux tools rely on is pairing <code>parsedmarc<\/code> with PostgreSQL and Grafana on Linux. An automated IMAP poller extracts incoming XML\/GZ attachments, resolves sender PTR records via a local caching DNS daemon, indexes authentication records into relational tables, and displays real-time deliverability dashboards.<\/p>\n<\/div>\n<h2 style=\"color:#001b41;font-size:26px;font-weight:700;margin-top:36px\">Deconstructing DMARC Aggregate (RUA) XML Payloads<\/h2>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Domain-based Message Authentication, Reporting, and Conformance (DMARC, RFC 7489) leverages two primary telemetry channels: Forensic Failure Reports (RUF) and Aggregate Feedback Reports (RUA). While RUF delivers real-time notifications of individual authentication failures (often redacted or suppressed by mailbox providers due to user privacy mandates), RUA provides the statistical backbone for domain defense.<\/p>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Aggregate reports arrive via SMTP as MIME emails with compressed XML attachments (typically <code>.xml.gz<\/code> or <code>.zip<\/code>). An aggregate XML document breaks down into three critical operational stanzas:<\/p>\n<ul style=\"color:#444;font-size:16px;line-height:1.7;padding-left:24px\">\n<li><strong style=\"color:#001b41\"><code>&lt;report_metadata&gt;<\/code>:<\/strong> Identifies the reporting organization (e.g., <code>google.com<\/code>, <code>enterprise.protection.outlook.com<\/code>), report identifier, contact address, and the UTC epoch timestamp interval.<\/li>\n<li><strong style=\"color:#001b41\"><code>&lt;policy_published&gt;<\/code>:<\/strong> Reflects the exact DNS DMARC record evaluated by the receiving mail transfer agent (MTA) at the time of delivery, including the base domain policy (<code>p<\/code>), subdomain policy (<code>sp<\/code>), DKIM\/SPF alignment mode (<code>adkim<\/code>, <code>aspf<\/code>), and sampling percentage (<code>pct<\/code>).<\/li>\n<li><strong style=\"color:#001b41\"><code>&lt;record&gt;<\/code>:<\/strong> Contains row-level delivery occurrences containing the connecting client IP address, volume count, evaluated message disposition (<code>none<\/code>, <code>quarantine<\/code>, or <code>reject<\/code>), alongside granular SPF and DKIM pass\/fail status and alignment checks.<\/li>\n<\/ul>\n<blockquote class=\"wp-block-quote\" style=\"background:#f9f9f9;border-left:4px solid #001b41;padding:16px 20px;margin:24px 0\">\n<p style=\"margin:0;color:#333;font-size:15px;line-height:1.6\"><strong style=\"color:#001b41\">Architecture Note:<\/strong> Alignment is distinct from cryptographic validity. An SPF check may return a <code>pass<\/code> for an authorized third-party mailer (e.g., SendGrid or Mailgun), but if the <code>RFC5321.MailFrom<\/code> bounce domain differs from the <code>RFC5322.From<\/code> header visible to the end user, DMARC SPF alignment fails. Your parsing pipeline must cleanly differentiate between raw protocol results and identifier alignment.<\/p>\n<\/blockquote>\n<h2 style=\"color:#001b41;font-size:26px;font-weight:700;margin-top:36px\">Comparative Performance Matrix: Open-Source DMARC Parsers<\/h2>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Linux administrators have several battle-tested open-source utilities to parse DMARC aggregate reports linux tools ecosystem provides. The table below contrasts traditional baseline scripting against tuned enterprise-ready parsing architectures under high volume (100,000+ daily message events across 50 domains):<\/p>\n<figure class=\"wp-block-table is-style-regular\">\n<table style=\"width:100%;border-collapse:collapse;margin:24px 0;font-size:15px;text-align:left\">\n<thead style=\"background:#001b41;color:#ffffff\">\n<tr>\n<th style=\"padding:12px 16px;border-bottom:2px solid #001b41\">Architecture Component<\/th>\n<th style=\"padding:12px 16px;border-bottom:2px solid #001b41\">Standard \/ Default Setup<\/th>\n<th style=\"padding:12px 16px;border-bottom:2px solid #001b41\">Tuned \/ Production Pipeline<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;font-weight:600\">Core Engine<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Ad-hoc Bash \/ Perl XML Grep<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">parsedmarc (Python 3 \/ asyncio)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;font-weight:600\">Mail Ingestion<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Manual POP3\/IMAP cron downloads<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Persistent IMAP IDLE \/ Postfix pipe<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;font-weight:600\">Data Storage<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Flat XML files \/ SQLite<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">PostgreSQL 16 (B-Tree + BRIN indexing)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;font-weight:600\">Reverse DNS (PTR)<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Synchronous upstream queries<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Local Unbound cache + Redis caching<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;font-weight:600\">1M Row Query Latency<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">14.8 seconds (full table scan)<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">38 ms (composite index scan)<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;font-weight:600\">Visualization<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7\">Static CSV exports \/ terminal output<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #e7e7e7;color:#20B038;font-weight:600\">Grafana dynamic dashboards &amp; alerts<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 style=\"color:#001b41;font-size:26px;font-weight:700;margin-top:36px\">Step-by-Step Production Setup: Deploying parsedmarc and PostgreSQL<\/h2>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">To construct an enterprise-grade reporting pipeline, we deploy <code>parsedmarc<\/code> backed by a dedicated PostgreSQL database and local caching resolvers. This section walks through configuring the database, service parameters, and Linux operating system optimizations.<\/p>\n<h3 style=\"color:#001b41;font-size:20px;font-weight:600;margin-top:24px\">1. Database Preparation and Partitioning Strategy<\/h3>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Log into PostgreSQL and create an isolated database user and database with optimal collation settings:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code>-- Create dedicated unprivileged DMARC telemetry user\nCREATE USER dmarc_worker WITH ENCRYPTED PASSWORD 'StrongProductionPasswordHere789!';\nCREATE DATABASE dmarc_db OWNER dmarc_worker ENCODING 'UTF8' LC_COLLATE 'C' LC_CTYPE 'C';\n\n-- Connect to target database\n\\c dmarc_db\n\n-- Grant schema rights\nGRANT ALL ON SCHEMA public TO dmarc_worker;\n\n-- Post-creation performance index (run after parsedmarc initial migration)\nCREATE INDEX CONCURRENTLY IF NOT EXISTS idx_dmarc_records_date_domain \nON dmarc_report_records (begin_date DESC, header_from, disposition);\n\nCREATE INDEX CONCURRENTLY IF NOT EXISTS idx_dmarc_records_source_ip \nON dmarc_report_records (source_ip_address);\n<\/code><\/pre>\n<h3 style=\"color:#001b41;font-size:20px;font-weight:600;margin-top:24px\">2. Configuring parsedmarc for Automated Processing<\/h3>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Install <code>parsedmarc<\/code> in an isolated Python virtual environment on Rocky Linux, AlmaLinux, Debian, or Ubuntu to prevent conflicting system-level pip packages:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># Install OS dependencies and Python virtual environment\nsudo apt-get update &amp;&amp; sudo apt-get install -y python3-venv python3-pip libpq-dev\n\n# Create dedicated system service user and folder hierarchy\nsudo useradd -r -s \/usr\/sbin\/nologin -d \/opt\/parsedmarc parsedmarc\nsudo mkdir -p \/opt\/parsedmarc \/etc\/parsedmarc\nsudo python3 -m venv \/opt\/parsedmarc\/venv\n\n# Install parsedmarc with PostgreSQL and Redis connectors\nsudo \/opt\/parsedmarc\/venv\/bin\/pip install --upgrade pip\nsudo \/opt\/parsedmarc\/venv\/bin\/pip install parsedmarc psycopg2-binary redis\n<\/code><\/pre>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Create the master configuration file at <code>\/etc\/parsedmarc\/parsedmarc.ini<\/code>. This configuration specifies IMAP mailbox polling, database persistence, and local Redis reverse-DNS caching:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code>[general]\nsave_aggregate = True\nsave_forensic = False\noutput_directory = \/opt\/parsedmarc\/archive\nlog_file = \/var\/log\/parsedmarc.log\nlog_level = WARNING\nnameservers = 127.0.0.1\n\n[imap]\nhost = imap.mail.example.com\nport = 993\nssl = True\nuser = dmarc-reports@example.com\npassword = SecureMailboxAppPassword123!\nwatch = True\nfolder = INBOX\narchive_folder = Processed\ndelete = False\ntest = False\n\n[postgres]\nhost = 127.0.0.1\nport = 5432\ndatabase = dmarc_db\nuser = dmarc_worker\npassword = StrongProductionPasswordHere789!\nssl = prefer\n\n[redis]\nhost = 127.0.0.1\nport = 6379\ndb = 0\nssl = False\n<\/code><\/pre>\n<blockquote class=\"wp-block-quote\" style=\"background:#f9f9f9;border-left:4px solid #001b41;padding:16px 20px;margin:24px 0\">\n<p style=\"margin:0;color:#333;font-size:15px;line-height:1.6\"><strong style=\"color:#001b41\">Security Tip:<\/strong> Set directory permissions to <code>0700<\/code> and configuration file permissions to <code>0600<\/code> owned by <code>parsedmarc:parsedmarc<\/code>. Avoid storing plain text credentials in repositories or world-readable files.<\/p>\n<\/blockquote>\n<h2 style=\"color:#001b41;font-size:26px;font-weight:700;margin-top:36px\">Optimizing Linux Kernel and Systemd Daemon Architecture<\/h2>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">High-throughput DMARC ingestion requires tuning kernel socket buffers and running the processor under a self-healing systemd supervisor. High-volume parsers trigger thousands of concurrent PTR lookups and database writes when backlogs occur.<\/p>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Apply kernel network tuning at <code>\/etc\/sysctl.d\/99-dmarc-parser.conf<\/code>:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code># \/etc\/sysctl.d\/99-dmarc-parser.conf\n# Optimize ephemeral port ranges and TCP recycling for high DNS\/IMAP traffic\nnet.ipv4.ip_local_port_range = 10240 65535\nnet.ipv4.tcp_fin_timeout = 15\nnet.ipv4.tcp_tw_reuse = 1\n\n# Socket memory allocations\nnet.core.somaxconn = 4096\nnet.core.netdev_max_backlog = 5000\nnet.ipv4.tcp_max_syn_backlog = 4096\n\n# System file descriptors for persistent parsing workers\nfs.file-max = 2097152\n<\/code><\/pre>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Load the new kernel parameters immediately by issuing <code>sudo sysctl --system<\/code>.<\/p>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Next, manage the ingestion daemon using a robust systemd service configuration at <code>\/etc\/systemd\/system\/parsedmarc.service<\/code>:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code>[Unit]\nDescription=Parsedmarc DMARC Aggregate Report Ingestion Service\nAfter=network.target postgresql.service redis.service unbound.service\nWants=network-online.target\n\n[Service]\nType=simple\nUser=parsedmarc\nGroup=parsedmarc\nWorkingDirectory=\/opt\/parsedmarc\nExecStart=\/opt\/parsedmarc\/venv\/bin\/parsedmarc -c \/etc\/parsedmarc\/parsedmarc.ini\nRestart=always\nRestartSec=15s\n\n# Hardening and Sandboxing\nNoNewPrivileges=true\nPrivateTmp=true\nProtectSystem=strict\nProtectHome=true\nReadWritePaths=\/opt\/parsedmarc \/var\/log\nLimitNOFILE=65536\n\n[Install]\nWantedBy=multi-user.target\n<\/code><\/pre>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Enable and verify the parsing service:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code>sudo systemctl daemon-reload\nsudo systemctl enable --now parsedmarc.service\nsudo systemctl status parsedmarc.service\n<\/code><\/pre>\n<h2 style=\"color:#001b41;font-size:26px;font-weight:700;margin-top:36px\">Grafana Deliverability Analytics and SQL Queries<\/h2>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Once telemetry flows into PostgreSQL, connect Grafana using the native PostgreSQL data source. Because <code>parsedmarc<\/code> structures metadata cleanly, administrators can run aggregate queries across millions of inbound report records with minimal overhead.<\/p>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Here is a production SQL query for an alerting panel identifying unauthorized sending servers emitting mail masquerading as your domain:<\/p>\n<pre class=\"wp-block-code\" style=\"background:#f3f3f3;color:#333;padding:16px;border-left:4px solid #001b41;font-family:monospace;font-size:13px\"><code>-- Detect high-volume unaligned senders failing both SPF and DKIM\nSELECT \n    source_ip_address,\n    source_reverse_dns,\n    header_from,\n    SUM(count) AS total_messages,\n    disposition,\n    spf_result,\n    dkim_result\nFROM dmarc_report_records\nWHERE \n    begin_date &gt;= NOW() - INTERVAL '7 days'\n    AND (spf_alignment = 'fail' OR spf_alignment IS NULL)\n    AND (dkim_alignment = 'fail' OR dkim_alignment IS NULL)\nGROUP BY \n    source_ip_address, source_reverse_dns, header_from, disposition, spf_result, dkim_result\nHAVING SUM(count) &gt; 25\nORDER BY total_messages DESC\nLIMIT 50;\n<\/code><\/pre>\n<blockquote class=\"wp-block-quote\" style=\"background:#f9f9f9;border-left:4px solid #001b41;padding:16px 20px;margin:24px 0\">\n<p style=\"margin:0;color:#333;font-size:15px;line-height:1.6\"><strong style=\"color:#001b41\">Deliverability Strategy:<\/strong> Before promoting your DNS record from <code>p=none<\/code> to <code>p=quarantine<\/code> and eventually <code>p=reject<\/code>, monitor this query for 30 consecutive days. Ensure all legitimate third-party services (CRM platforms, transaction relays, notification gateways) achieve 100% DKIM or SPF alignment.<\/p>\n<\/blockquote>\n<h2 style=\"color:#001b41;font-size:26px;font-weight:700;margin-top:36px\">Scaling Infrastructure and Production Readiness<\/h2>\n<p style=\"color:#444;font-size:16px;line-height:1.7\">Running internal analytics pipelines alongside live email servers requires strict resource isolation. Mail parsing processes must never starve incoming SMTP listeners of CPU or disk I\/O bandwidth. For critical commercial operations where mail deliverability and uptime directly impact revenue, deploying dedicated database and monitoring nodes on <a href=\"https:\/\/merahost.org\" target=\"_blank\" rel=\"noopener\">MeraHost Enterprise Cloud<\/a> ensures enterprise NVMe I\/O performance, dedicated CPU pinning, and zero resource contention.<\/p>\n<h2 style=\"color:#001b41;font-size:26px;font-weight:700;margin-top:36px\">Frequently Asked Questions<\/h2>\n<details class=\"wp-block-group\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:4px;padding:14px;margin-bottom:12px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#001b41\">How frequently should DMARC aggregate reports be ingested on Linux?<\/summary>\n<p style=\"margin-top:10px;color:#444\">Most major mail receivers (Gmail, Microsoft 365, Yahoo) send aggregate reports once every 24 hours (governed by the <code>ri=86400<\/code> parameter in your DMARC DNS record). Setting your parsing service or systemd timer to process incoming mailboxes every 2 to 4 hours provides optimal operational latency without creating unneeded IMAP polling overhead.<\/p>\n<\/details>\n<details class=\"wp-block-group\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:4px;padding:14px;margin-bottom:12px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#001b41\">What is the functional difference between RUA and RUF DMARC reports?<\/summary>\n<p style=\"margin-top:10px;color:#444\">RUA reports are aggregated XML documents containing volume summaries, authentication pass\/fail stats, and IP addresses sent across a reporting interval. RUF reports are individual forensic messages containing the full headers and sometimes message bodies of specific failed emails. Due to GDPR and PII privacy concerns, most major providers no longer emit RUF reports, making RUA aggregate parsing the gold standard for authentication monitoring.<\/p>\n<\/details>\n<details class=\"wp-block-group\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:4px;padding:14px;margin-bottom:12px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#001b41\">Why do legitimate forwarded messages fail SPF alignment in DMARC reports?<\/summary>\n<p style=\"margin-top:10px;color:#444\">When an email is forwarded (such as via an academic institution or mailing list), the forwarding server&#8217;s IP address connects to the final recipient&#8217;s MTA. Because the forwarding server is not listed in your domain&#8217;s SPF record, SPF checks fail. DMARC accounts for this through DKIM: as long as the cryptographic DKIM signature remains unaltered during transit, the message achieves DMARC alignment and passes evaluation.<\/p>\n<\/details>\n<details class=\"wp-block-group\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:4px;padding:14px;margin-bottom:12px\">\n<summary style=\"cursor:pointer;font-weight:600;color:#001b41\">How can I prevent reverse DNS (PTR) lookups from freezing the parser?<\/summary>\n<p style=\"margin-top:10px;color:#444\">DMARC aggregate reports contain hundreds of unique IP addresses. If your parser attempts synchronous external DNS lookups for each IP, upstream DNS timeouts can stall your ingestion process. To solve this, deploy a local caching DNS recursive resolver (such as Unbound) listening on <code>127.0.0.1<\/code> and enable Redis caching in your <code>parsedmarc.ini<\/code> configuration.<\/p>\n<\/details>\n<div class=\"wp-block-group has-background\" style=\"background:#f9f9f9;border:1px solid #e7e7e7;border-radius:8px;padding:32px;margin:40px 0;text-align:center\">\n<h3 style=\"color:#001b41;margin-top:0;font-size:24px;font-weight:700\">Deploy Enterprise-Grade Production Infrastructure<\/h3>\n<p style=\"color:#444;font-size:16px;line-height:1.6;max-width:680px;margin:12px auto 24px auto\">Need guaranteed performance with zero price hikes? Host mission-critical workloads on <strong style=\"color:#001b41\">MeraHost<\/strong> with pure Enterprise NVMe, LiteSpeed Web Server, and Same Renewal Price, Always (starting at \u20b999\/mo).<\/p>\n<div class=\"wp-block-buttons\" style=\"display:flex;gap:16px;justify-content:center;flex-wrap:wrap\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link\" href=\"https:\/\/merahost.org\" style=\"background:#001b41;color:#ffffff;font-weight:700;padding:12px 28px;border-radius:4px;text-decoration:none;display:inline-block;font-size:15px\" target=\"_blank\" rel=\"noopener\">Explore MeraHost NVMe Cloud &rarr;<\/a><\/div>\n<div class=\"wp-block-button is-style-outline\"><a class=\"wp-block-button__link\" href=\"https:\/\/cpanelfree.com\" style=\"background:transparent;color:#001b41;font-weight:600;padding:12px 24px;border:2px solid #001b41;border-radius:4px;text-decoration:none;display:inline-block;font-size:15px\">Deploy Free Staging on CpanelFree<\/a><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Parse and analyze DMARC aggregate XML reports on Linux using open-source engines. Automate ingestion, database storage, and Grafana deliverability dashboards.<\/p>\n","protected":false},"author":1,"featured_media":4878,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[205],"tags":[57,177,87,206,101],"class_list":["post-4879","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-deliverability","tag-almalinux","tag-databases-performance","tag-devops","tag-email-deliverability","tag-sysadmin"],"_links":{"self":[{"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/posts\/4879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/comments?post=4879"}],"version-history":[{"count":0,"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/posts\/4879\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/media\/4878"}],"wp:attachment":[{"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/media?parent=4879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/categories?post=4879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cpanelfree.com\/blog\/wp-json\/wp\/v2\/tags?post=4879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}