<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="marf-parameters.xsl"?>
<?xml-model href="marf-parameters.rng" schematypens="http://relaxng.org/ns/structure/1.0" ?>
<registry xmlns="http://www.iana.org/assignments" id="marf-parameters">
  <title>Messaging Abuse Reporting Format (MARF) Parameters</title>
  <created>2010-05-26</created>
  <updated>2026-01-09</updated>
  <registry id="marf-parameters-1">
    <title>Feedback Report Header Fields</title>
    <xref type="rfc" data="rfc5965"/>
    <registration_rule>Specification Required</registration_rule>
    <expert>Scott Kitterman, Murray Kucherawy</expert>
    <record>
      <name>Arrival-Date</name>
      <description>date/time the original message was received</description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Auth-Failure</name>
      <description>Type of email authentication method failure</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>Authentication-Results</name>
      <description>results of authentication check(s)</description>
      <multiple>Yes</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Delivery-Result</name>
      <description>Final disposition of the subject message</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>DKIM-ADSP-DNS</name>
      <description>Retrieved DKIM ADSP record</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>DKIM-Canonicalized-Body</name>
      <description>Canonicalized body, per DKIM</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>DKIM-Canonicalized-Header</name>
      <description>Canonicalized header, per DKIM</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>DKIM-Domain</name>
      <description>DKIM signing domain from "d=" tag</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>DKIM-Identity</name>
      <description>Identity from DKIM signature</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>DKIM-Selector</name>
      <description>Selector from DKIM signature</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>DKIM-Selector-DNS</name>
      <description>Retrieved DKIM key record</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>Feedback-Type</name>
      <description>registered feedback report type</description>
      <multiple>No</multiple>
      <related>N/A</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Incidents</name>
      <description>expression of how many similar incidents are represented by this report</description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Original-Mail-From</name>
      <description>email address used in the MAIL FROM portion of the original SMTP transaction
      </description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Original-Rcpt-To</name>
      <description>email address used in the RCPT TO portion of the original SMTP transaction
      </description>
      <multiple>Yes</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Received-Date</name>
      <description>date/time the original message was received (replaced by "Arrival-Date")</description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>historic</status>
    </record>
    <record>
      <name>Reported-Domain</name>
      <description>a domain name the report generator considers to be key to the 
        message about which a report is being generated</description>
      <multiple>Yes</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Reported-URI</name>
      <description>a URI the report generator considers to be key
        to the message about which a report is being
        generated
      </description>
      <multiple>Yes</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Reporting-MTA</name>
      <description>MTA generating this report</description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Source-IP</name>
      <description>IPv4 or IPv6 address from which the original message
        was received
      </description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>SPF-DNS</name>
      <description>Retrieved SPF record</description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>User-Agent</name>
      <description>name and version of the program generating the report</description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Version</name>
      <description>version of specification used</description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>Source-Port</name>
      <description>TCP source port from which the original message was received</description>
      <multiple>No</multiple>
      <related>any</related>
      <xref type="rfc" data="rfc6692"/>
      <status>current</status>
    </record>
    <record updated="2026-01-09">
      <name>Identity-Alignment</name>
      <description>indicates whether the message about which a report is
      being generated had any identifiers in alignment as defined in 
        <xref type="draft" data="RFC-ietf-dmarc-failure-reporting-24"/></description>
      <multiple>No</multiple>
      <related>auth-failure</related>
      <xref type="draft" data="RFC-ietf-dmarc-failure-reporting-24"/>
      <status>current</status>
    </record>
    
  </registry>
  <registry id="marf-parameters-2">
    <title>Feedback Report Type Values</title>
    <xref type="rfc" data="rfc5965"/>
    <registration_rule>Specification Required</registration_rule>
    <expert>Scott Kitterman, Murray Kucherawy</expert>
    <record>
      <name>abuse</name>
      <description>unsolicited email or some other kind of email abuse</description>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>auth-failure</name>
      <description>email authentication failure report</description>
      <xref type="rfc" data="rfc6591"/>
      <status>current</status>
    </record>
    <record>
      <name>fraud</name>
      <description>indicates some kind of fraud or phishing activity</description>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>not-spam</name>
      <description>Indicates that the entity providing the report does not
        consider the message to be spam.  This may be used to correct a
        message that was incorrectly tagged or categorized as spam.</description>
      <xref type="rfc" data="rfc6430"/>
      <status>current</status>
    </record>
    <record>
      <name>other</name>
      <description>any other feedback that does not fit into other registered types</description>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
    <record>
      <name>virus</name>
      <description>report of a virus found in the originating message</description>
      <xref type="rfc" data="rfc5965"/>
      <status>current</status>
    </record>
  </registry>
  <people/>
</registry>
