Dmarc Overview

Troubleshoot DMARC problems

Find your symptom, check the likely cause, and apply the fix.

Data and reports

Symptom Likely cause Fix
No data for a new domain Reports take one to two days; DNS not published or not propagated Check Tools > DMARC, then wait 48 hours
Domain card shows the warning "not sending DMARC+ reports" rua missing or not pointing at your DMARC+ address Add the address shown in the DMARC tool
Domain status is Not published No TXT record at _dmarc.<domain> Publish a record
Managed record not resolving A TXT record still exists at the same name as the CNAME, or the CNAME has the wrong target Remove the TXT, recheck the CNAME value
Some receivers appear but not others Not every receiver sends reports Normal. Judge by the largest receivers.
Volume drops suddenly The record was changed or removed; report delivery interrupted Check the DMARC tool, confirm the rua value
Forensic page is empty Few receivers send failure reports Normal. Use aggregate data.
Numbers differ between pages Some views count SPF and DKIM together; others count what receivers did See Understand aggregate report data
Recent days look low The latest day is still arriving Compare complete days
Weekly email missing Module off, spam folder, or no domains See Weekly and PDF reports

Authentication failures

Symptom Likely cause Fix
SPF passes, DMARC fails SPF domain does not match the From domain Align the return path, or make DKIM pass and align
DKIM passes, DMARC fails Signing domain is the vendor's, not yours Configure custom domain signing at the vendor
SPF shows a permanent error More than 10 lookups, or two SPF records Fix with the SPF tool
DKIM not found Wrong selector or record not published Enter the correct selector
Mail passes for your servers but fails after being forwarded Forwarding changes the sending IP, so SPF fails Rely on DKIM; ask the forwarder to preserve DKIM
Mailing list mail fails The list changes the subject or body, breaking the signature, and uses its own IP Ask the list to rewrite From, or accept these failures
Unknown IP with high volume failing Third-party sender or spoofing Identify with PTR name and Aggregate Reports Explorer

After moving to enforcement

Symptom Likely cause Fix
Legitimate mail is missing A sender fails DMARC and is now quarantined or rejected Lower pct or the policy, fix the sender, and retry
A new tool's mail goes to spam New sender not authenticated Set it up. See Managing third-party senders
Internal alerts from devices stopped Devices send from your domain without authentication Route them through an authenticated relay

Common mistakes

Mistake Better approach
Jumping straight to reject Monitor first, then phase in with pct
Ignoring subdomains Set sp or publish subdomain records
Two SPF records Keep exactly one
Publishing a DMARC record with no report address Always include rua
Using -all before senders are known Use ~all until the reports are clean
Forgetting to add new tools Add every new sender before it goes live
Leaving a TXT at _dmarc when adding a managed CNAME Delete the TXT first
Judging by SPF alone DMARC needs alignment
Never reviewing after go-live Review weekly

Still stuck

Collect the domain, the date range, and a screenshot of Tools > DMARC and contact support.