RUFReader
Every failed message, laid open.
Aggregate reports tell you how many messages failed DMARC. Forensic reports show you which ones: a copy of each failure, sent back as a coded attachment. RUFReader opens them on your own machine and shows who sent what, from where, and why it failed.
Coming soon. Your reports stay on your machine, and it is bought once.
- Someone spoofing your domain?
- Your own sender, not set up?
- Forwarded, changed on the way?
The who, the where and the why
A forensic report is a few kilobytes of headers and codes. RUFReader will turn each one into a case you can read in seconds, then line the cases up so the pattern stands out.
RUFReader is being built now. This is what it will show.Failure reports, opened
Point it at the report emails you have saved, or a folder of them, and it pulls out the failure details and the original headers.
No mailbox connection, no account, nothing to set up first.Who sent it
The From address, the return path behind it and the subject line, as the receiving server reported them.
The address on show is often not the one that actually sent it.Where it came from
The sending IP address, its reverse DNS name, and whether it belongs to a service you recognise or one you have never heard of.
A known mail service reads very differently from a bare address with no name.Why it failed
SPF, DKIM and alignment side by side, with one plain sentence on what they mean together.
Signed, but by someone else's domain, is the classic one.Spoof or misconfiguration
A real service that is not set up for your domain needs a fix. A stranger using your name needs enforcement. RUFReader says which looks more likely.
The difference between a DNS change and a policy change.Patterns, not just messages
Failures grouped by source and by sender address, so a campaign shows up as one line rather than three hundred emails.
The view you need before moving to quarantine or reject.Forensic reports can hold real mail.
A failure report can carry real addresses, subject lines and, from some providers, part of the message itself. That is exactly the data that should not be uploaded to somebody else's service. RUFReader reads it where it already is.
Processed on your machine
Reports are opened and analysed locally. No upload, no account, no ScryMarc server in the path.
Lookups you control
Naming a sending server uses ordinary DNS. Anything beyond that, such as a location for an address, is optional and can be switched off.
No telemetry
It does not report back on how you use it or what is in your reports. Your mail never comes anywhere near us.
The headline, then the evidence.
TrustedMARC reads the daily aggregate reports and tells you how much mail fails, and from where. RUFReader reads the forensic reports and shows you the messages themselves. Each works alone. Together, you find the problem in one and prove it in the other.
- Every sender, named
- How much fails, and the trend
- The DNS fixes to make
- The failing messages themselves
- Who, where and why, per message
- Spoof or misconfiguration
From report to reason
Forensic reports only arrive if your DMARC record asks for them.
Publish a ruf address
Add one to your DMARC record, such as ruf=mailto:dmarc-ruf@yourco.co.uk, plus fo=1 so you hear about any failed check, not only total failure.
Keep them somewhere safe
Send them to a dedicated mailbox, not someone's inbox. They hold copies of real message headers, so treat that mailbox as sensitive.
See who and why
Hand the saved reports to RUFReader. Every failing message laid open, grouped by where it came from.
Who it is for
Security teams
See the phishing that uses your name, from the messages themselves, without sending samples to an outside service.
Email admins
Find the legitimate sender you forgot to put in SPF or sign with DKIM, before you move to quarantine or reject.
MSPs and consultants
Investigate client domains on your own machine and hand back a clear account of what failed and why.
Bought once. Priced at launch.
RUFReader will be a one-off purchase, like every ScryMarc tool. Get notified and the price comes to you first.
Questions
What is a forensic report?
When a receiving mail server sees a message that claims to be from your domain but fails DMARC, it can send you a report about that one message, with its headers and authentication results. The ruf tag in your DMARC record says where to send them. They are also called failure reports.
How is this different from TrustedMARC?
TrustedMARC reads aggregate reports, the daily summaries of how much mail passed and failed. RUFReader reads forensic reports, the individual failed messages. Together they give you the count and the evidence.
Will I actually receive any?
Probably some, but far fewer than aggregate reports. Several large mailbox providers do not send forensic reports at all, for privacy reasons, and some strip parts out. When they do arrive, they are often the best evidence you will get.
Does it send my reports anywhere?
No. It reads them on your machine. There is no ScryMarc server and no telemetry.
Why the name?
RUF is the tag in a DMARC record that asks for forensic reports. RUFReader reads them.
When is it out?
It is being built now, alongside TrustedMARC. Get notified and you will hear first, with the price and the platforms it ships on.
Hear first when it is ready.
Get notified at launchMore from ScryMarc Software
Small, local-first desktop tools that each do one job properly. Bought once, no subscriptions.