Symptoms#
- Messages landing in spam despite previously good placement
- Bounces mentioning policy, authentication, or reputation
- Provider dashboards showing a drop in reputation or authentication pass rate
Diagnosis steps#
- Confirm the configuration is live: query DNS from an external resolver and check the sending platform's settings page.
- Send to a seed mailbox and read the full headers, especially Authentication-Results.
- Compare the domains in From, Return-Path, and DKIM d= for alignment.
- Check provider dashboards (Google Postmaster Tools, Microsoft SNDS) for reputation and error rates.
- Review recent changes: new vendors, DNS edits, list imports, volume spikes.
Likely causes#
- Jumping straight to p=reject and blocking your own invoicing or HR system.
- Sending RUA reports to a mailbox nobody reads; use a report processor.
- Leaving subdomains uncovered because sp= was never set.
- Assuming p=none provides protection; it is monitoring only.
Fix and re-verify#
- Confirm SPF and DKIM are deployed and aligned for every legitimate sender.
- Publish _dmarc.yourdomain.com with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com to begin collecting reports.
- Analyze aggregate (RUA) reports for 2 to 4 weeks to identify unauthenticated legitimate sources.
- Fix each source, then move to p=quarantine with pct=25, ramping to 100.
- Move to p=reject and add sp=reject to cover subdomains.
Frequently asked questions#
What is DMARC alignment?
The domain in the visible From header must match (exactly or organizationally) the domain that passed SPF or DKIM. Set adkim=s and aspf=s for strict matching.
How long until I can reach p=reject?
Typically 4 to 12 weeks depending on how many third-party senders you have to fix.
What are RUA and RUF reports?
RUA are daily aggregate XML reports of pass/fail counts per source. RUF are per-message forensic samples; many receivers no longer send them.