Forensic Analysis: individual failed messages
Aggregate reports tell you that 40 messages failed from some IP. Forensic reports tell you which messages, with subject lines and timestamps. That level of detail is what lets you say "that was our payroll system" instead of guessing.
- Where to find it
- Reports → Forensic Analysis
What you'll see
A table of failures showing the time, subject, source IP, a trust badge (same colours as Sending Sources), separate SPF and DKIM pass/fail badges, and the failure type. Click a row to open the detail view. Where the reporting server included enough raw data, DMARCS reconstructs the authentication header for that exact message.
Why the table may look thin
Not every mailbox provider sends forensic reports; Google, for example, doesn't. So this page only has entries from the receivers that do. That's normal, and it's why the aggregate views on the Dashboard remain the main source of truth for volumes.
When to use it
- A trusted sender shows as failing and you want to see an actual example to understand why.
- You suspect a targeted spoofing campaign and want the subject lines being used.
- You want to check whether a failure is forwarding (harmless) or a genuine misconfiguration.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.