DIAGNOSTIC PLAYBOOK

Why DMARC forensic reports may never arrive

A ruf address does not guarantee message-level failure reports. Receiver support and privacy decisions limit these reports, so an empty forensic inbox cannot establish that no failures occurred.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Confirm that the ruf syntax and mailbox are valid without relying on this as your only monitoring channel.
  2. Review aggregate reports for failure evidence and identify which receivers supply them.
  3. Collect controlled message samples or logs for deeper investigation where authorized.

What this looks like

ILLUSTRATIVE EXAMPLE

Your aggregate dashboard shows alignment failures, but no corresponding forensic emails arrive. The receiver may not provide that report type.

A mistake to avoid

Do not broaden access to message-level reports just to increase visibility. They can contain sensitive message information and need restricted handling.

Keep the result in context

DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.