RUA is the address in your DMARC record that receives aggregate reports: who sent mail using your domain, and whether SPF and DKIM aligned. It does not block fake email by itself.
RUA is the address in your DMARC record that receives aggregate reports: who sent mail using your domain, and whether SPF and DKIM aligned. It does not block fake email by itself.
What the RUA tag is
A DMARC record is a TXT at _dmarc.yourdomain. The rua tag lists one or more URIs, almost always mailto: addresses, where receivers should send aggregate feedback. A minimal start looks like this:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain
Receivers that support DMARC reporting send XML, usually once a day. Each file covers a time window, the policy you published, and rows per source: IP address, message count, SPF result, DKIM result, and whether they aligned with the From domain.
RUA is reporting. The p= tag is policy. People searching for DMARC RUA often want both: where the reports go, and what to do with them before they move off p=none.
RUA versus RUF
RUA is aggregate. Counts and authentication results by source. No message body. This is the operational report.
RUF is forensic. Optional samples of failing messages. Volume, privacy and uneven receiver support make RUF a poor default. Most organisations publish RUA only.
MailControl workflows focus on RUA. If you already have a personal mailbox in rua= and nobody reads it, you have a record without a programme.
What you should see in a report
Which organisations sent the report (large mailbox providers are the usual sources).
Sources that pass alignment: your real mail platform, and tools you have authorised.
Sources that fail: a forgotten newsletter, a ticketing tool on the wrong domain, or someone sending fake email as you.
How receivers applied your policy (none, quarantine, or reject) for that window.
The first files often arrive after a day or two, not in the first hour. An empty RUA inbox on day one is normal.
Why RUA comes before reject
p=none with RUA is the safe start against email spoofing. You learn every legitimate sender (SPF includes, DKIM selectors, third-party tools) before you ask receivers to drop failures. Moving to quarantine or reject without that list blocks mail you still need.
SPF flattening and DKIM alignment show up here as well. A source that fails because the SPF record hit the ten-lookup limit looks the same in RUA as a source you never authorised, until you separate them. Read SPF flattening and What is DKIM? if the same vendor fails every day.
When the report address is on another domain
If the mailbox in rua= is not on the same domain as the DMARC record, the receiving domain must authorise those reports. Otherwise many receivers will not send them. Hosted MailControl RUA is set up so that authorisation is part of the record the portal shows you. Do not point RUA at a random external address and assume the XML will arrive.
How NovaMX MailControl hosts RUA
DMARC Reports ingests the aggregate XML and shows source summaries in My NovaMX. You do not need to open the files. Managed DMARC guides the policy text from monitor to reject and does not store the reports. Many teams use both, or a MailControl bundle that already includes reporting plus SPF flattening.
You do not need NovaMX hosting. Verify the domain, publish the _dmarc TXT where your DNS already lives, and wait for the first reports. The free mail check shows whether a DMARC record is public before you order anything.
Pitfalls
RUA pointed at an unread mailbox.
Expecting RUA to stop spoofing. Only p=quarantine or p=reject asks receivers to act.
Tightening policy from one noisy day instead of a week or two of clean sources.
Forgetting that RUA does not cover lookalike domains or display-name spoofing.
Publishing DMARC before SPF and DKIM exist, so every row fails and the report is noise.
Common questions
What does DMARC RUA mean?
RUA is the URI in a DMARC record where receivers send aggregate reports. Those reports summarise who sent mail using your domain and whether SPF and DKIM aligned.
What is the difference between RUA and RUF?
RUA is aggregate daily XML summaries. RUF is optional forensic samples of failing messages. Most organisations start with RUA only.
Does RUA stop email spoofing?
No. RUA only collects reports. The DMARC policy tag (p=quarantine or p=reject) is what asks receivers to act on failing mail.
Can MailControl host my RUA address?
Yes. DMARC Reports, and MailControl bundles that include reporting, host the RUA address and show source summaries in My NovaMX instead of raw XML.
RUA is het adres in uw DMARC-record dat aggregaatrapporten ontvangt: wie mail met uw domein verstuurde, en of SPF en DKIM aligned waren. Het blokkeert nepmail niet vanzelf.
Wat de RUA-tag is
Een DMARC-record is een TXT op _dmarc.uwdomein. De tag rua noemt één of meer URI's, bijna altijd mailto:-adressen, waar ontvangers aggregaatfeedback naartoe sturen. Een minimale start ziet er zo uit:
v=DMARC1; p=none; rua=mailto:dmarc@uwdomein
Ontvangers die DMARC-rapportage ondersteunen sturen XML, meestal één keer per dag. Elk bestand dekt een tijdvenster, het beleid dat u publiceerde, en rijen per bron: IP-adres, aantal berichten, SPF-resultaat, DKIM-resultaat, en of die overeenkwamen met het From-domein.
RUA is rapportage. De tag p= is beleid. Wie op DMARC RUA zoekt, wil meestal beide: waar de rapporten heen gaan, en wat u ermee doet voordat u p=none verlaat.
RUA tegenover RUF
RUA is aggregaat. Tellingen en authenticatieresultaten per bron. Geen berichtinhoud. Dit is het operationele rapport.
RUF is forensisch. Optionele samples van falende berichten. Volume, privacy en wisselende ondersteuning maken RUF een slechte standaard. De meeste organisaties publiceren alleen RUA.
MailControl-workflows richten zich op RUA. Staat er al een persoonlijke mailbox in rua= die niemand leest, dan heeft u een record zonder programma.
Wat u in een rapport hoort te zien
Welke organisaties het rapport stuurden (grote mailboxproviders zijn de gebruikelijke bronnen).
Bronnen die alignment halen: uw echte mailplatform, en tools die u heeft geautoriseerd.
Bronnen die falen: een vergeten nieuwsbrief, een ticketsysteem op het verkeerde domein, of iemand die nepmail namens u stuurt.
Hoe ontvangers uw beleid toepasten (none, quarantine of reject) in dat venster.
De eerste bestanden komen vaak na een dag of twee, niet in het eerste uur. Een lege RUA-inbox op dag één is normaal.
Waarom RUA vóór reject komt
p=none met RUA is de veilige start tegen e-mail spoofing. U leert elke legitieme afzender (SPF-includes, DKIM-selectors, tools van derden) voordat u ontvangers vraagt fouten te laten vallen. Naar quarantine of reject gaan zonder die lijst blokkeert mail die u nog nodig heeft.
SPF-flattening en DKIM-alignment duiken hier ook op. Een bron die faalt omdat het SPF-record de limiet van tien lookups raakte, lijkt in RUA hetzelfde als een bron die u nooit autoriseerde, tot u ze uit elkaar haalt. Lees SPF-flattening en Wat is DKIM? als dezelfde leverancier elke dag faalt.
Wanneer het rapportadres op een ander domein staat
Staat de mailbox in rua= niet op hetzelfde domein als het DMARC-record, dan moet het ontvangende domein die rapporten autoriseren. Anders sturen veel ontvangers ze niet. Gehoste MailControl-RUA is zo opgezet dat die autorisatie in het record zit dat het portaal toont. Wijs RUA niet naar een willekeurig extern adres en neem aan dat de XML vanzelf komt.
Hoe NovaMX MailControl RUA host
DMARC Reports neemt de aggregaat-XML in en toont bronoverzichten in My NovaMX. U hoeft de bestanden niet te openen. Managed DMARC begeleidt de beleidstekst van monitor naar reject en bewaart de rapporten niet. Veel teams gebruiken beide, of een MailControl-bundel die rapportage plus SPF-flattening al bevat.
U heeft geen NovaMX-hosting nodig. Verifieer het domein, publiceer de _dmarc-TXT waar uw DNS al staat, en wacht op de eerste rapporten. De gratis mailcheck toont of een DMARC-record publiek is voordat u iets bestelt.
Valkuilen
RUA naar een ongelezen mailbox.
Verwachten dat RUA spoofing stopt. Alleen p=quarantine of p=reject vraagt ontvangers om te handelen.
Beleid aanscherpen op één rumoerige dag in plaats van een week of twee schone bronnen.
Vergeten dat RUA geen lookalike-domeinen of spoofing van de weergavenaam dekt.
DMARC publiceren voordat SPF en DKIM bestaan, zodat elke rij faalt en het rapport ruis is.
Veelgestelde vragen
Wat betekent DMARC RUA?
RUA is de URI in een DMARC-record waar ontvangers aggregaatrapporten naartoe sturen. Die rapporten vatten samen wie mail met uw domein verstuurde en of SPF en DKIM aligned waren.
Wat is het verschil tussen RUA en RUF?
RUA zijn aggregaat dagelijkse XML-samenvattingen. RUF zijn optionele forensische samples van falende berichten. De meeste organisaties beginnen alleen met RUA.
Stopt RUA e-mail spoofing?
Nee. RUA verzamelt alleen rapporten. De DMARC-beleidstag (p=quarantine of p=reject) vraagt ontvangers om te handelen bij falende mail.
Kan MailControl mijn RUA-adres hosten?
Ja. DMARC Reports, en MailControl-bundels met rapportage, hosten het RUA-adres en tonen bronoverzichten in My NovaMX in plaats van ruwe XML.