WQI.web​qualityindex

Email health

DMARC Failure Reports (RUF)

Per-message forensic reports for DMARC failures — distinct from the daily aggregate (rua=) feed. Useful for live debugging; rare in practice because of privacy concerns.

Authority
IETF
Version
RFC 7489 §7.3
Jurisdiction
Global
Source
datatracker.ietf.org
Last reviewed
2026-04-28
Last verified
pending

What it is

DMARC Failure (forensic) Reporting — RFC 7489 §7.3. The `ruf=` tag on a DMARC record requests redacted copies of individual messages that fail authentication, formatted per the Authentication Failure Reporting Format (AFRF, RFC 6591).

Why it matters

RUF gives per-message visibility — what header the spoofer used, what selector failed — that aggregate reports flatten away. Most major receivers (Gmail, Microsoft) have stopped sending RUF for privacy reasons, so coverage is thin; useful when investigating a specific incident, less so as ongoing telemetry.

Who it applies to

Senders investigating active spoofing campaigns or running mature email-security operations.

How WQI scores it

Web Quality Index considers this standard satisfied when the supporting factor passes.

# Factor Status
1 DMARC enforcement live

Related standards

Requires
DMARC
See also
DMARC

Standards that share factors with this one

Auto-computed from overlapping factor tickets in satisfiedBy, excluding standards already listed under "See also" above. Strong overlap suggests these standards rise and fall together when sites are scored.

Other references