DMARC Forensic Report Reader
Decode DMARC forensic (RUF) failure reports in AFRF format. See the source IP, authentication results and original headers — free, processed in your browser.
Read a DMARC forensic report
Paste a forensic (ruf) failure report in AFRF format to decode its fields.
What this forensic report reader does
Common use cases
- 1Investigating a specific spoofing attempt
- 2Understanding why one message failed DMARC
- 3Identifying a misconfigured legitimate sender
- 4Gathering evidence of brand abuse
- 5Reviewing ruf reports without extra tooling
- 6Confirming an attacker's source IP and target
Related tools
About DMARC forensic reports
Forensic (RUF) reports are sent to the address in your DMARC ruf tag when an individual message fails authentication. Unlike aggregate reports, each one covers a single failed message and includes redacted headers — useful for investigating spoofing or a broken legitimate source. Note that many providers no longer send them for privacy reasons.
This reader parses the AFRF format entirely in your browser. Because forensic reports can contain personal data, nothing you paste is uploaded. Pair it with aggregate reports for the full picture, then tighten SPF, DKIM and your DMARC policy accordingly.
More Free Tools Where This Came From
This utility is one of dozens of free, no-login tools for DNS, email, SEO and developers — all instant and private.
HostCloud.in · Pune, India · Serving 34,987+ Websites Since 2020
Got Questions? We Have Answers.
What is a DMARC forensic report?
A forensic (RUF) report is sent to your DMARC ruf address when a single message fails authentication. It includes the source and redacted original headers, useful for investigating spoofing.
How is it different from an aggregate report?
Aggregate reports summarise volume and alignment across all sources daily; forensic reports cover one failed message each and include header details.
Why do I rarely receive forensic reports?
Many providers stopped sending them for privacy reasons, since they can contain personal data. Aggregate reports remain the primary data source.
Is the pasted report uploaded?
No. It is parsed entirely in your browser. Because forensic reports may contain personal data, nothing you paste leaves your device.
What format do forensic reports use?
The AFRF format (RFC 5965): a machine-readable feedback section plus the original message headers. This reader extracts the key fields from both.
What should I do after reading one?
Determine whether the source is a spoofer or a misconfigured legitimate sender, then tighten SPF/DKIM or your DMARC policy accordingly.
