Dmarc Overview

Manage third-party senders

Third-party senders are services that send mail using your domain: marketing platforms, support desks, billing systems, CRMs, HR tools and monitoring alerts. Most DMARC failures during rollout come from these.

How to find them

  1. Open DMARC+ > Dashboard and check Report Sources for the last 30 days.
  2. Open the Aggregate Reports Explorer and sort by volume with DMARC failing.
  3. Ask teams which tools send email on their behalf. Compare the list with what you find.

Make a sender pass DMARC

A sender passes when either SPF or DKIM passes and aligns with your From domain. DKIM is normally the better route, because it survives forwarding.

Approach What to ask the vendor Result
Custom DKIM signing "Can you sign with our domain?" They usually give DNS records to publish Aligned DKIM pass
Custom return path "Can we use a subdomain as the bounce domain?" Aligned SPF pass
SPF include "What do we add to SPF?" SPF passes, but only aligned if the return path uses your domain
Sending from a subdomain Give the vendor its own subdomain, for example news.example.com Separate policy and clearer reports

Tip: a dedicated subdomain per vendor makes reports easy to read and limits damage from a misconfigured service.

Steps for each vendor

  1. Ask the vendor for its domain authentication instructions. Look for terms like "domain authentication", "custom DKIM" or "sender domain".
  2. Publish the records the vendor gives you.
  3. Have the vendor verify the domain in its own console.
  4. Send a test message.
  5. Confirm in the Aggregate Reports Explorer that its IPs show DMARC pass, after a day or two.

Note: this guide does not describe individual vendors' screens because they change often. Use each vendor's documentation.

Mind the SPF limit

Each include counts toward the 10 lookup limit. If you have many vendors:

  • Move vendors to subdomains with their own SPF records.
  • Remove vendors you no longer use.
  • Consider a managed SPF record. See Managed record tools.

When a vendor cannot align

Some services cannot sign with your domain or use your return path. Choose one:

Option Trade-off
Replace the vendor Cleanest
Send from the vendor's own domain Change the From address
Keep a lower policy on that subdomain Weakens protection on that subdomain

Ongoing controls

  • Require a security review before a new tool sends as your domain.
  • Add new sources to your records before launch.
  • Review Report Sources monthly.
  • Remove sources you retire.