DMARC ruf= forensic reports: should you remove them?
Forensic (ruf) reports can contain parts of real emails, and most big providers no longer send them. Why removing ruf= is usually simplest.
By the Domain Health Hub team · Updated
- ruf= asks receivers for a report on each failing message, which can include its headers or content.
- That can mean personal data arriving in a mailbox you may not control, with GDPR duties attached.
- Gmail and most other large providers don't send them, so removing ruf= usually loses very little.
What it means
The DMARC record has a ruf= tag. Where rua= asks for daily totals, ruf= asks for a failure report about individual messages, as defined in RFC 7489. The fo= tag controls when they are sent. This is an information note, not a failure: it doesn't affect the grade.
Why it matters
A failure report can include the failing message's headers, and sometimes its content: names, email addresses, subject lines. Under UK and EU GDPR, whoever receives those reports is handling personal data, often from people who have nothing to do with you. If the ruf= address belongs to a third party you no longer use, that data still goes to them.
In practice, Gmail and most other large mailbox providers don't send failure reports at all, for exactly this reason, and the few that do often redact them. The aggregate reports from rua= tell you almost everything you need to fix your senders.
How to confirm it
How to fix it
Remove the ruf= tag, and fo= with it, which only affects failure reports. Keep everything else.
- Before
- v=DMARC1; p=reject; rua=mailto:dmarc@example.com; ruf=mailto:x@vendor.example; fo=1
- After
- v=DMARC1; p=reject; rua=mailto:dmarc@example.com
If you do want failure reports, send them to a mailbox you control, limit who can read it, and set a retention period.
Cloudflare DNS
- Open the domain in the Cloudflare dashboard and go to DNS, then Records.
- Add a record of type TXT with the name
_dmarc. Cloudflare adds the domain for you. - Paste the record as the content and save.
Microsoft 365
Microsoft 365 doesn't publish DMARC for your own domain: the record goes wherever the domain's DNS is hosted (your registrar, Cloudflare or similar). Only the onmicrosoft.com domain, or a domain whose DNS Microsoft hosts, is managed in the Microsoft 365 admin centre. Turn on DKIM in the Defender portal before you tighten the policy, so Microsoft 365 email passes on DKIM as well as SPF.
Google Workspace
The same applies: add the TXT record at your DNS host. Make sure Gmail is signing with DKIM for your domain first (Admin console, Apps, Google Workspace, Gmail, Authenticate email), or forwarded email will fail DMARC once you move past p=none.
Questions
Does removing ruf= affect my DMARC policy?
No. It only stops requests for forensic reports. Policy and aggregate reports are untouched.
Does Domain Health Hub accept forensic reports?
No. We only accept aggregate reports, and keep only the totals from them.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.