DMARC Engine
Home/Glossary/Forensic report (RUF)
Glossary

Forensic report (RUF)

DMARC forensic (RUF) reports are per-message failure samples sent in near real time when a message fails DMARC.

Forensic reports, also called failure reports, are configured with the ruf= tag in your _dmarc record and defined in RFC 7489. Unlike aggregate reports, which summarise volumes over a day, a forensic report is generated for an individual message at the moment it fails DMARC, and it is sent in near real time.

These reports can include far more detail, such as message headers and sometimes parts of the body, which makes them useful for investigating a specific phishing or spoofing campaign against your domain. The fo= tag controls when they are generated, for example fo=1 requests a report whenever any underlying SPF or DKIM check fails to align.

In practice forensic reports are rarely sent. Because the samples can contain personal data, most large receivers, including Gmail and others, do not emit them at all for privacy and regulatory reasons. You should therefore treat them as an occasional bonus, never as your primary source of truth.

Build your DMARC programme around aggregate reports and a policy progression to enforcement; use any forensic samples that do arrive to confirm what the aggregate data already shows.

Check it on your domain

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.