Virtual RUF Reports
Virtual RUF reports provide administrators with message-level visibility for emails that fail DMARC authentication.
Many email providers do not send DMARC failure (RUF/forensic) reports. As a result, administrators often cannot identify which specific message failed DMARC authentication or determine the reason for the failure.
When Email Security detects an email that fails DMARC while it is being processed in the Email Security network, it generates a virtual RUF report based on the available message details. These virtual reports enable administrators to troubleshoot and investigate issues more quickly while supporting shared insights across the Check Point network.
If Check Point RUF - Opt-out is enabled in DMARC Configuration, the customer chooses not to participate in this capability. In this case, Email Security continues to evaluate DMARC for incoming messages but does not generate, share, or receive virtual RUF reports.
Opting out reduces forensic visibility for DMARC failures and limits the ability to benefit from collective insights gathered across the Check Point network.