ScryMarc Software
RUFReader Get notified

RUFReader

Every failed message, laid open.

Aggregate reports tell you how many messages failed DMARC. Forensic reports show you which ones: a copy of each failure, sent back as a coded attachment. RUFReader opens them on your own machine and shows who sent what, from where, and why it failed.

Coming soon. Your reports stay on your machine, and it is bought once.

Forensic reports12 this weekyourco.co.uk
  • Someone spoofing your domain?
  • Your own sender, not set up?
  • Forwarded, changed on the way?
?sources behind them, once opened
Illustrative reports for an example domain. RUFReader reads the ones your DMARC record asks for.

The who, the where and the why

A forensic report is a few kilobytes of headers and codes. RUFReader will turn each one into a case you can read in seconds, then line the cases up so the pattern stands out.

RUFReader is being built now. This is what it will show.

Failure reports, opened

Point it at the report emails you have saved, or a folder of them, and it pulls out the failure details and the original headers.

No mailbox connection, no account, nothing to set up first.

Who sent it

The From address, the return path behind it and the subject line, as the receiving server reported them.

The address on show is often not the one that actually sent it.

Where it came from

The sending IP address, its reverse DNS name, and whether it belongs to a service you recognise or one you have never heard of.

A known mail service reads very differently from a bare address with no name.

Why it failed

SPF, DKIM and alignment side by side, with one plain sentence on what they mean together.

Signed, but by someone else's domain, is the classic one.

Spoof or misconfiguration

A real service that is not set up for your domain needs a fix. A stranger using your name needs enforcement. RUFReader says which looks more likely.

The difference between a DNS change and a policy change.

Patterns, not just messages

Failures grouped by source and by sender address, so a campaign shows up as one line rather than three hundred emails.

The view you need before moving to quarantine or reject.

Forensic reports can hold real mail.

A failure report can carry real addresses, subject lines and, from some providers, part of the message itself. That is exactly the data that should not be uploaded to somebody else's service. RUFReader reads it where it already is.

Processed on your machine

Reports are opened and analysed locally. No upload, no account, no ScryMarc server in the path.

Lookups you control

Naming a sending server uses ordinary DNS. Anything beyond that, such as a location for an address, is optional and can be switched off.

No telemetry

It does not report back on how you use it or what is in your reports. Your mail never comes anywhere near us.

The headline, then the evidence.

TrustedMARC reads the daily aggregate reports and tells you how much mail fails, and from where. RUFReader reads the forensic reports and shows you the messages themselves. Each works alone. Together, you find the problem in one and prove it in the other.

TrustedMARCAggregate reports (rua). Available now.
  • Every sender, named
  • How much fails, and the trend
  • The DNS fixes to make
RUFReaderForensic reports (ruf). Coming soon.
  • The failing messages themselves
  • Who, where and why, per message
  • Spoof or misconfiguration

From report to reason

Forensic reports only arrive if your DMARC record asks for them.

1. Ask

Publish a ruf address

Add one to your DMARC record, such as ruf=mailto:[email protected], plus fo=1 so you hear about any failed check, not only total failure.

2. Collect

Keep them somewhere safe

Send them to a dedicated mailbox, not someone's inbox. They hold copies of real message headers, so treat that mailbox as sensitive.

3. Read

See who and why

Hand the saved reports to RUFReader. Every failing message laid open, grouped by where it came from.

Who it is for

Security teams

See the phishing that uses your name, from the messages themselves, without sending samples to an outside service.

Email admins

Find the legitimate sender you forgot to put in SPF or sign with DKIM, before you move to quarantine or reject.

MSPs and consultants

Investigate client domains on your own machine and hand back a clear account of what failed and why.

Bought once. Priced at launch.

RUFReader will be a one-off purchase, like every ScryMarc tool. Get notified and the price comes to you first.

No subscription, everReading your own reports should not become another monthly bill.
Every 1.x update is freeWhen version 2 arrives, owners are offered it at a discount. Happy on version 1? Stay on it.
Better with TrustedMARCAggregate and forensic, both read on your own machine. TrustedMARC is available now.

Questions

What is a forensic report?

When a receiving mail server sees a message that claims to be from your domain but fails DMARC, it can send you a report about that one message, with its headers and authentication results. The ruf tag in your DMARC record says where to send them. They are also called failure reports.

How is this different from TrustedMARC?

TrustedMARC reads aggregate reports, the daily summaries of how much mail passed and failed. RUFReader reads forensic reports, the individual failed messages. Together they give you the count and the evidence.

Will I actually receive any?

Probably some, but far fewer than aggregate reports. Several large mailbox providers do not send forensic reports at all, for privacy reasons, and some strip parts out. When they do arrive, they are often the best evidence you will get.

Does it send my reports anywhere?

No. It reads them on your machine. There is no ScryMarc server and no telemetry.

Why the name?

RUF is the tag in a DMARC record that asks for forensic reports. RUFReader reads them.

When is it out?

It is being built now, alongside TrustedMARC. Get notified and you will hear first, with the price and the platforms it ships on.

Hear first when it is ready.

Get notified at launch