Forensic reports
Forensic reports (also called failure reports) are copies or summaries of individual messages that failed DMARC. They help you identify spoofing attempts. Open them from DMARC+ > Forensic Reports.
What to expect
| Point | Detail |
|---|---|
| Availability | Only some receivers send forensic reports. Many large providers do not, so an empty page is normal. |
| Trigger | Your DMARC record's ruf address and the fo setting control when reports are requested |
| Contents | Message details such as subject, recipient, source IP and sender address |
| Personal data | Reports can contain personal information from the failed message. Restrict access and keep them only as long as you need. |
Note: an empty Forensic Reports page does not mean nothing is failing. Use the Aggregate Reports Explorer for volume and source data.
Turn on forensic reporting
- Open DMARC+ > Manage > Managed DMARC or Tools > DMARC > DMARC Generator.
- Make sure the forensic report address (
ruf) is the DMARC+ address shown by the tool. - Choose a failure reporting option.
fo value |
Report when |
|---|---|
| 0 | All authentication mechanisms fail (default) |
| 1 | Any mechanism fails |
| d | DKIM fails |
| s | SPF fails |
- Publish the record.
Tip: fo=1 gives the most reports and is useful during investigation. Use it for a limited time.
Read the page
| Section | What it shows |
|---|---|
| Domains Reporting Failures | Your domains that have received failure reports |
| Source IP Address | Sending IPs, labelled as sender addresses that are probably spoofed |
| Reports table | Feedback Type, Subject, Original Recipient, Arrival Date, Reported Domain, Source IP Address and Sender Address |
Use the data
- Look for the same source IP appearing repeatedly. This suggests a campaign.
- Compare the sender address with your real senders. A real sender that fails needs an SPF or DKIM fix.
- Cross-check the IP in the Aggregate Reports Explorer.
- For confirmed spoofing, move toward an enforced policy. See From monitoring to enforcement.
Privacy checklist
- Give access only to people who handle abuse and security.
- Do not forward report contents outside the security team.
- Delete or archive reports you no longer need under your retention rules.