Virtual RUF Reports

Virtual RUF reports provide administrators with message-level visibility for emails that fail DMARC authentication.

Many email providers do not send DMARC failure (RUF/forensic) reports. As a result, administrators often cannot identify which specific message failed DMARC authentication or determine the reason for the failure.

When Email Security detects an email that fails DMARC while it is being processed in the Email Security network, it generates a virtual RUF report based on the available message details. These virtual reports enable administrators to troubleshoot and investigate issues more quickly while supporting shared insights across the Check Point network.

If Check Point RUF - Opt-out is enabled in DMARC Configuration, the customer chooses not to participate in this capability. In this case, Email Security continues to evaluate DMARC for incoming messages but does not generate, share, or receive virtual RUF reports.

Opting out reduces forensic visibility for DMARC failures and limits the ability to benefit from collective insights gathered across the Check Point network.

External Reporting Authorization Record

To make sure that the DMARC records for your domain are accepted by Check Point, after you add the Check Point hosted mailbox to your DMARC record, Check Point automatically adds an External Reporting Authorization Record.

It creates a domain name in the format: <your_domain>.com._report._dmarc.dmarc-cp.com. In this domain, a TXT record is added with this content: "v=DMARC1":

Text

Description

TXT

<your_domain>.com._report._dmarc.dmarc-cp.com

Note:

This process could take a couple of hours after Check Point detects the update to your DMARC record.