February 9, 20267 min read

DMARC Aggregate vs Forensic Reports: What's the Difference?

Aggregate reports (rua) provide daily summaries of authentication results across all emails from your domain. Forensic reports (ruf) contain details of individual messages that failed DMARC. Aggregate reports are essential for monitoring; forensic reports help debug specific failures but have limited availability due to privacy concerns.

Aggregate Reports (rua)

Aggregate reports are the primary DMARC monitoring tool.

What They Contain

How to Receive Them

Add rua tag to your DMARC record:

v=DMARC1; p=none; rua=mailto:[email protected]

Report Frequency

Use Cases

Aggregate Reports Are Essential

Every DMARC implementation should include rua for aggregate reports. They are the foundation of DMARC monitoring and provide the data needed to safely progress toward enforcement.

Forensic Reports (ruf)

Forensic reports provide details about individual failed messages.

What They Contain

How to Receive Them

Add ruf tag to your DMARC record:

v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected]

Availability Issues

Many providers do not send forensic reports:

Privacy concerns limit forensic report adoption.

Use Cases

Key Differences

Scope

Detail Level

Privacy Impact

Volume

Practical Recommendations

Always Use Aggregate Reports

Forensic Reports: Optional

Failure Reporting Options

The fo tag controls when forensic reports generate:

Managing Report Volume

Aggregate Reports

Forensic Reports

Frequently Asked Questions

Do I need forensic reports if I have aggregate reports?
For most organizations, aggregate reports are sufficient. Forensic reports help with specific debugging but are not essential. Start with aggregate only and add forensic if you need detailed failure investigation.
Why doesn't Gmail send forensic reports?
Gmail cites privacy concerns. Forensic reports can contain message content and recipient information. Gmail provides aggregate reports but protects individual message privacy by not sending forensic data.
Can I use the same email address for rua and ruf?
Technically yes, but not recommended. Forensic reports can generate high volume and would overwhelm your aggregate report mailbox. Use separate addresses for easier management.
How do I process the XML files I receive?
Use a DMARC report analyzer service or tool. These parse the XML, aggregate data across multiple reports, and provide dashboards and alerts. Manual XML review is impractical at scale.

Master DMARC Reporting

SortedIQ helps senders implement and interpret DMARC reports effectively.

Talk to Our Team