Email Deliverability
DMARC Policy Failure
DMARC (Domain-based Message Authentication, Reporting & Conformance) builds on SPF and DKIM to prevent email spoofing. A DMARC failure means neither SPF nor DKIM passed with proper alignment to the From: domain. With p=reject or p=quarantine policies, failing emails are blocked or sent to spam.
Symptoms
- Legitimate emails rejected or quarantined
- DMARC aggregate reports showing high failure rates
- Recipients reporting emails going to spam
Common Causes
- SPF and DKIM both failing or not aligned with the From: domain
- Third-party services sending on your behalf without proper delegation
- Forwarding services modifying the From: header
- Misconfigured DMARC record syntax
Step-by-Step Troubleshooting
- 1
Check DMARC record
Validate DMARC record syntax, policy, and reporting configuration.
Use DMARC Check β - 2
- 3
Validate DKIM
Ensure DKIM passes and the d= domain aligns with the From: domain.
Use DKIM Validator β - 4
Analyze email headers
Inspect authentication results in email headers to identify which mechanism is failing.
Use Email Headers β
Recommended Diagnostic Tools
Monitor DMARC Compliance
Track DMARC authentication results and alignment.

