Find your symptom, check the likely cause, and apply the fix.
Data and reports
| Symptom |
Likely cause |
Fix |
| No data for a new domain |
Reports take one to two days; DNS not published or not propagated |
Check Tools > DMARC, then wait 48 hours |
| Domain card shows the warning "not sending DMARC+ reports" |
rua missing or not pointing at your DMARC+ address |
Add the address shown in the DMARC tool |
| Domain status is Not published |
No TXT record at _dmarc.<domain> |
Publish a record |
| Managed record not resolving |
A TXT record still exists at the same name as the CNAME, or the CNAME has the wrong target |
Remove the TXT, recheck the CNAME value |
| Some receivers appear but not others |
Not every receiver sends reports |
Normal. Judge by the largest receivers. |
| Volume drops suddenly |
The record was changed or removed; report delivery interrupted |
Check the DMARC tool, confirm the rua value |
| Forensic page is empty |
Few receivers send failure reports |
Normal. Use aggregate data. |
| Numbers differ between pages |
Some views count SPF and DKIM together; others count what receivers did |
See Understand aggregate report data |
| Recent days look low |
The latest day is still arriving |
Compare complete days |
| Weekly email missing |
Module off, spam folder, or no domains |
See Weekly and PDF reports |
Authentication failures
| Symptom |
Likely cause |
Fix |
| SPF passes, DMARC fails |
SPF domain does not match the From domain |
Align the return path, or make DKIM pass and align |
| DKIM passes, DMARC fails |
Signing domain is the vendor's, not yours |
Configure custom domain signing at the vendor |
| SPF shows a permanent error |
More than 10 lookups, or two SPF records |
Fix with the SPF tool |
| DKIM not found |
Wrong selector or record not published |
Enter the correct selector |
| Mail passes for your servers but fails after being forwarded |
Forwarding changes the sending IP, so SPF fails |
Rely on DKIM; ask the forwarder to preserve DKIM |
| Mailing list mail fails |
The list changes the subject or body, breaking the signature, and uses its own IP |
Ask the list to rewrite From, or accept these failures |
| Unknown IP with high volume failing |
Third-party sender or spoofing |
Identify with PTR name and Aggregate Reports Explorer |
After moving to enforcement
| Symptom |
Likely cause |
Fix |
| Legitimate mail is missing |
A sender fails DMARC and is now quarantined or rejected |
Lower pct or the policy, fix the sender, and retry |
| A new tool's mail goes to spam |
New sender not authenticated |
Set it up. See Managing third-party senders |
| Internal alerts from devices stopped |
Devices send from your domain without authentication |
Route them through an authenticated relay |
Common mistakes
| Mistake |
Better approach |
Jumping straight to reject |
Monitor first, then phase in with pct |
| Ignoring subdomains |
Set sp or publish subdomain records |
| Two SPF records |
Keep exactly one |
| Publishing a DMARC record with no report address |
Always include rua |
Using -all before senders are known |
Use ~all until the reports are clean |
| Forgetting to add new tools |
Add every new sender before it goes live |
Leaving a TXT at _dmarc when adding a managed CNAME |
Delete the TXT first |
| Judging by SPF alone |
DMARC needs alignment |
| Never reviewing after go-live |
Review weekly |
Still stuck
Collect the domain, the date range, and a screenshot of Tools > DMARC and contact support.