Symptoms#
- Messages landing in spam despite previously good placement
- Bounces mentioning policy, authentication, or reputation
- Provider dashboards showing a drop in reputation or authentication pass rate
Diagnosis steps#
- Confirm the configuration is live: query DNS from an external resolver and check the sending platform's settings page.
- Send to a seed mailbox and read the full headers, especially Authentication-Results.
- Compare the domains in From, Return-Path, and DKIM d= for alignment.
- Check provider dashboards (Google Postmaster Tools, Microsoft SNDS) for reputation and error rates.
- Review recent changes: new vendors, DNS edits, list imports, volume spikes.
Likely causes#
- Reading raw XML by hand and giving up after day two.
- Ignoring low-volume unknown sources that turn out to be your own systems.
- Expecting RUF reports; most large providers no longer send them.
Fix and re-verify#
- Publish rua=mailto: pointing to a dedicated mailbox or a report processor.
- Collect reports for at least two weeks before drawing conclusions.
- Group sources by IP owner and match each to a known vendor.
- Fix alignment for legitimate sources; treat unknown high-volume sources as spoofing.
- Track pass rate weekly and tighten policy as it approaches 100%.
Frequently asked questions#
How do I read a DMARC report?
Each record lists a source IP, message count, SPF and DKIM results, and alignment. Use an analyzer to aggregate by source; the goal is to name every IP range.
Why do I see mail from IPs I do not recognize?
Common causes are forwarding, a vendor you forgot, an employee's personal tool, or spoofing. Volume and geography usually tell them apart.