Email authentication

DMARC Forensic Report Reader

Decode DMARC forensic (RUF) failure reports in AFRF format. See the source IP, authentication results and original headers — free, processed in your browser.

Read a DMARC forensic report

Paste a forensic (ruf) failure report in AFRF format to decode its fields.

What this forensic report reader does

Decodes AFRF (RFC 5965) forensic failure reports
Extracts source IP, arrival date and reported domain
Surfaces the authentication results and failure type
Shows the original From, To, Subject and Message-ID
Flags SPF and DKIM failures for the source
Processes everything locally — nothing is uploaded

Common use cases

  1. 1Investigating a specific spoofing attempt
  2. 2Understanding why one message failed DMARC
  3. 3Identifying a misconfigured legitimate sender
  4. 4Gathering evidence of brand abuse
  5. 5Reviewing ruf reports without extra tooling
  6. 6Confirming an attacker's source IP and target

Related tools

About DMARC forensic reports

Forensic (RUF) reports are sent to the address in your DMARC ruf tag when an individual message fails authentication. Unlike aggregate reports, each one covers a single failed message and includes redacted headers — useful for investigating spoofing or a broken legitimate source. Note that many providers no longer send them for privacy reasons.

This reader parses the AFRF format entirely in your browser. Because forensic reports can contain personal data, nothing you paste is uploaded. Pair it with aggregate reports for the full picture, then tighten SPF, DKIM and your DMARC policy accordingly.

More Free Tools Where This Came From

This utility is one of dozens of free, no-login tools for DNS, email, SEO and developers — all instant and private.

HostCloud.in  ·  Pune, India  ·  Serving 34,987+ Websites Since 2020

FREQUENTLY ASKED QUESTIONS

Got Questions? We Have Answers.

What is a DMARC forensic report?

A forensic (RUF) report is sent to your DMARC ruf address when a single message fails authentication. It includes the source and redacted original headers, useful for investigating spoofing.

How is it different from an aggregate report?

Aggregate reports summarise volume and alignment across all sources daily; forensic reports cover one failed message each and include header details.

Why do I rarely receive forensic reports?

Many providers stopped sending them for privacy reasons, since they can contain personal data. Aggregate reports remain the primary data source.

Is the pasted report uploaded?

No. It is parsed entirely in your browser. Because forensic reports may contain personal data, nothing you paste leaves your device.

What format do forensic reports use?

The AFRF format (RFC 5965): a machine-readable feedback section plus the original message headers. This reader extracts the key fields from both.

What should I do after reading one?

Determine whether the source is a spoofer or a misconfigured legitimate sender, then tighten SPF/DKIM or your DMARC policy accordingly.