Read your DMARC XML report.
See sending IPs, message counts, authentication alignment and receiver actions. Find the failing groups worth investigating first.
Example: 128 messages, eight DMARC failures
This illustrative report for example.com contains two message groups:
| Source IP | Messages | DMARC | Receiver action |
|---|---|---|---|
| 192.0.2.10 | 120 | Pass through aligned DKIM | No DMARC action |
| 198.51.100.20 | 8 | Fail: SPF and DKIM unaligned or failed | Quarantine |
Start with the eight failing messages. Confirm whether that IP belongs to a service you use, then inspect the authentication evidence. A failure alone cannot tell you whether a sender is legitimate.