Skip to content

Arf feedback report

Feedback

Version

ARF format version.

A number. Default: 1. Name in the API: version.

Feedback Type

Type of feedback being reported.

One of: Message was reported as abusive or unwanted (abuse), Message failed authentication checks (authFailure), Message was reported as fraudulent (fraud), Message was incorrectly classified as spam (notSpam), Message contained a virus (virus), Other feedback type (other). Name in the API: feedbackType.

Delivery Result

What happened to the original message.

One of: Message was delivered to recipient (delivered), Message was delivered to spam folder (spam), Message was handled according to policy (policy), Message was rejected (reject), Other delivery result (other), Delivery result not specified (unspecified). Name in the API: deliveryResult.

Incidents

Number of incidents represented by this report.

A number. Default: 0. Name in the API: incidents.

Arrival Date

When the original message arrived.

A date and time. Name in the API: arrivalDate.

Source

Source IP

IP address of the original message source.

An IP address. Name in the API: sourceIp.

Source Port

Port of the original message source.

A number. Name in the API: sourcePort.

Reporting MTA

Hostname of the MTA generating this report.

Text. Name in the API: reportingMta.

User Agent

Software that generated this report.

Text. Name in the API: userAgent.

Original Message

Envelope ID

Original SMTP envelope ID (ENVID)

Text. Name in the API: originalEnvelopeId.

MAIL FROM

Original envelope sender address (MAIL FROM)

An email address. Name in the API: originalMailFrom.

RCPT TO

Original envelope recipient address (RCPT TO)

An email address. Name in the API: originalRcptTo.

Reported Domains

Domains being reported.

A list. Each one: text. Name in the API: reportedDomains.

Reported URIs

URIs being reported.

A list. Each one: an address (URL). Name in the API: reportedUris.

Authentication

Authentication Results

Authentication-Results header values from the original message.

A list. Each one: text. Name in the API: authenticationResults.

Auth Failure Type

Type of authentication failure (for auth-failure reports)

One of: DKIM ADSP policy failure (adsp), DKIM body hash verification failed (bodyHash), DKIM key has been revoked (revoked), DKIM signature verification failed (signature), SPF authentication failed (spf), DMARC authentication failed (dmarc), Authentication failure type not specified (unspecified). Name in the API: authFailure.

Identity Alignment

Which identities were aligned.

One of: No identity alignment (none), SPF identity aligned (spf), DKIM identity aligned (dkim), Both DKIM and SPF identities aligned (dkimSpf), Identity alignment not specified (unspecified). Name in the API: identityAlignment.

DKIM Details

DKIM Domain

Domain from the DKIM signature.

Text. Name in the API: dkimDomain.

DKIM Selector

Selector from the DKIM signature.

Text. Name in the API: dkimSelector.

DKIM Identity

Identity from the DKIM signature (i= tag)

Text. Name in the API: dkimIdentity.

ADSP DNS Record

DKIM ADSP DNS record content.

Text. Name in the API: dkimAdspDns.

Selector DNS Record

DKIM selector DNS record content.

Text. Name in the API: dkimSelectorDns.

Canonicalized Headers

Message headers after DKIM canonicalization.

Text. Name in the API: dkimCanonicalizedHeader.

Canonicalized Body

Message body after DKIM canonicalization.

Text. Name in the API: dkimCanonicalizedBody.

SPF Details

SPF DNS Record

SPF DNS record content.

Text. Name in the API: spfDns.

Original Content

Original Headers

Original message headers that triggered the report.

Text. Name in the API: headers.

Original Message

Original message content that triggered the report.

Text. Name in the API: message.