Dmarc Overview

Forensic reports

Forensic reports (also called failure reports) are copies or summaries of individual messages that failed DMARC. They help you identify spoofing attempts. Open them from DMARC+ > Forensic Reports.

What to expect

Point Detail
Availability Only some receivers send forensic reports. Many large providers do not, so an empty page is normal.
Trigger Your DMARC record's ruf address and the fo setting control when reports are requested
Contents Message details such as subject, recipient, source IP and sender address
Personal data Reports can contain personal information from the failed message. Restrict access and keep them only as long as you need.

Note: an empty Forensic Reports page does not mean nothing is failing. Use the Aggregate Reports Explorer for volume and source data.

Turn on forensic reporting

  1. Open DMARC+ > Manage > Managed DMARC or Tools > DMARC > DMARC Generator.
  2. Make sure the forensic report address (ruf) is the DMARC+ address shown by the tool.
  3. Choose a failure reporting option.
fo value Report when
0 All authentication mechanisms fail (default)
1 Any mechanism fails
d DKIM fails
s SPF fails
  1. Publish the record.

Tip: fo=1 gives the most reports and is useful during investigation. Use it for a limited time.

Read the page

Section What it shows
Domains Reporting Failures Your domains that have received failure reports
Source IP Address Sending IPs, labelled as sender addresses that are probably spoofed
Reports table Feedback Type, Subject, Original Recipient, Arrival Date, Reported Domain, Source IP Address and Sender Address

Use the data

  1. Look for the same source IP appearing repeatedly. This suggests a campaign.
  2. Compare the sender address with your real senders. A real sender that fails needs an SPF or DKIM fix.
  3. Cross-check the IP in the Aggregate Reports Explorer.
  4. For confirmed spoofing, move toward an enforced policy. See From monitoring to enforcement.

Privacy checklist

  • Give access only to people who handle abuse and security.
  • Do not forward report contents outside the security team.
  • Delete or archive reports you no longer need under your retention rules.