A forensic report unlike an aggregate report is essentially a copy of the email that failed DMARC validation and is typically sent immediately after the failure. Any personally identifiable information is removed from the email but information that may help in troubleshooting the DMARC failure should be included ie. any SPF and DKIM failures.

The receiver for the failure reports is denoted by the “ruf” tag in your DMARC record.

You can also specify the type of failures you would like to receive forensics for by using the “fo” tag in your DMARC record. By default, failure reports are sent when both SPF and DKIM fail.