Manage third-party senders
Third-party senders are services that send mail using your domain: marketing platforms, support desks, billing systems, CRMs, HR tools and monitoring alerts. Most DMARC failures during rollout come from these.
How to find them
- Open DMARC+ > Dashboard and check Report Sources for the last 30 days.
- Open the Aggregate Reports Explorer and sort by volume with DMARC failing.
- Ask teams which tools send email on their behalf. Compare the list with what you find.
Make a sender pass DMARC
A sender passes when either SPF or DKIM passes and aligns with your From domain. DKIM is normally the better route, because it survives forwarding.
| Approach | What to ask the vendor | Result |
|---|---|---|
| Custom DKIM signing | "Can you sign with our domain?" They usually give DNS records to publish | Aligned DKIM pass |
| Custom return path | "Can we use a subdomain as the bounce domain?" | Aligned SPF pass |
| SPF include | "What do we add to SPF?" | SPF passes, but only aligned if the return path uses your domain |
| Sending from a subdomain | Give the vendor its own subdomain, for example news.example.com |
Separate policy and clearer reports |
Tip: a dedicated subdomain per vendor makes reports easy to read and limits damage from a misconfigured service.
Steps for each vendor
- Ask the vendor for its domain authentication instructions. Look for terms like "domain authentication", "custom DKIM" or "sender domain".
- Publish the records the vendor gives you.
- Have the vendor verify the domain in its own console.
- Send a test message.
- Confirm in the Aggregate Reports Explorer that its IPs show DMARC pass, after a day or two.
Note: this guide does not describe individual vendors' screens because they change often. Use each vendor's documentation.
Mind the SPF limit
Each include counts toward the 10 lookup limit. If you have many vendors:
- Move vendors to subdomains with their own SPF records.
- Remove vendors you no longer use.
- Consider a managed SPF record. See Managed record tools.
When a vendor cannot align
Some services cannot sign with your domain or use your return path. Choose one:
| Option | Trade-off |
|---|---|
| Replace the vendor | Cleanest |
| Send from the vendor's own domain | Change the From address |
| Keep a lower policy on that subdomain | Weakens protection on that subdomain |
Ongoing controls
- Require a security review before a new tool sends as your domain.
- Add new sources to your records before launch.
- Review Report Sources monthly.
- Remove sources you retire.