Forensic reports, also called failure reports, are configured with the ruf= tag in your _dmarc record and defined in RFC 7489. Unlike aggregate reports, which summarise volumes over a day, a forensic report is generated for an individual message at the moment it fails DMARC, and it is sent in near real time.
These reports can include far more detail, such as message headers and sometimes parts of the body, which makes them useful for investigating a specific phishing or spoofing campaign against your domain. The fo= tag controls when they are generated, for example fo=1 requests a report whenever any underlying SPF or DKIM check fails to align.
In practice forensic reports are rarely sent. Because the samples can contain personal data, most large receivers, including Gmail and others, do not emit them at all for privacy and regulatory reasons. You should therefore treat them as an occasional bonus, never as your primary source of truth.
Build your DMARC programme around aggregate reports and a policy progression to enforcement; use any forensic samples that do arrive to confirm what the aggregate data already shows.
Check it on your domain
- DMARC Checker: look up and validate a domain's DMARC record and policy.
- DMARC Report Analyser: read a DMARC aggregate (RUA) report in plain English.
- DMARC Generator: build a valid DMARC record from a simple form.