Is it safe to turn DMARC enforcement on?
Upload one of the aggregate reports already landing in your rua mailbox. You get the only number that decides it: how many messages would be rejected if you moved to p=reject today, and which senders are responsible.
Where do I find one?
They arrive daily at whatever address your rua= tag points at, from Google, Microsoft, Yahoo and others. Attachments are named something like google.com!acme.com!1788480000.xml.gz.
No reports arriving at all? That is usually an unauthorised external destination — the receiving domain has to opt in. How to fix that.
What happens to my file
It is read in memory, analysed and thrown away. Nothing is written to disk or to a database, and no account is involved.
That is deliberate. An aggregate report lists every server that sends mail for your domain, which is precisely the reconnaissance an attacker would want. The safest place to keep it is nowhere.
What this is not
This reads a report you already have. It does not collect them for you — that needs a receiving mail endpoint and continuous parsing at scale, and it is what dmarcian and EasyDMARC charge for. If you want ongoing collection, buy it from them. What Mailward monitors is the DNS side: whether your records are correct today, and an email the day they change.
Check the records behind the report
A report tells you what receivers saw yesterday. A scan tells you what your DNS says right now.