Email Deliverability

DMARC Policy Failure

DMARC (Domain-based Message Authentication, Reporting & Conformance) builds on SPF and DKIM to prevent email spoofing. A DMARC failure means neither SPF nor DKIM passed with proper alignment to the From: domain. With p=reject or p=quarantine policies, failing emails are blocked or sent to spam.

Symptoms

  • Legitimate emails rejected or quarantined
  • DMARC aggregate reports showing high failure rates
  • Recipients reporting emails going to spam

Common Causes

  • SPF and DKIM both failing or not aligned with the From: domain
  • Third-party services sending on your behalf without proper delegation
  • Forwarding services modifying the From: header
  • Misconfigured DMARC record syntax

Step-by-Step Troubleshooting

  1. 1

    Check DMARC record

    Validate DMARC record syntax, policy, and reporting configuration.

    Use DMARC Check β†’
  2. 2

    Validate SPF

    Ensure SPF passes and is aligned with the From: domain.

    Use SPF Checker β†’
  3. 3

    Validate DKIM

    Ensure DKIM passes and the d= domain aligns with the From: domain.

    Use DKIM Validator β†’
  4. 4

    Analyze email headers

    Inspect authentication results in email headers to identify which mechanism is failing.

    Use Email Headers β†’

Recommended Diagnostic Tools

Monitor DMARC Compliance

Track DMARC authentication results and alignment.

Frequently Asked Questions