DMARC fail: what it means and how to fix it
What dmarc=fail means, how to read it in the Authentication-Results header, and how to fix SPF and DKIM alignment for services and forwarded mail.
On this page
- What dmarc=fail means
- How to read the Authentication-Results header
- Why DMARC fails
- A service sends with its own domain
- Forwarding and mailing lists
- A server missing from SPF, or a changed message
- Strict alignment
- How to fix it
- 1. Find the sender that fails
- 2. Sign DKIM with your domain
- 3. Or align the MAIL FROM, and publish SPF on it
- 4. Use a dedicated subdomain if the service supports it
- 5. Keep relaxed alignment
- What happens to mail that fails
- Check your records
- Sources
dmarc=fail means a DMARC policy applies to the domain in the message's From address, but neither Sender Policy Framework (SPF) (opens in a new tab) nor DomainKeys Identified Mail (DKIM) (opens in a new tab) passed for a domain aligned with it (RFC 9989 section 5.3 (opens in a new tab)). One aligned pass from either is enough. To fix it, have the service that failed sign DKIM with your domain, or send with a MAIL FROM domain aligned with yours (Microsoft (opens in a new tab)).
What dmarc=fail means
RFC 9989 (opens in a new tab), which obsoletes RFC 7489, defines DMARC (Domain-based Message Authentication, Reporting, and Conformance). DMARC checks the domain in the message's From address, using two other checks:
- SPF checks the sending server. The owner of the MAIL FROM (envelope sender) domain publishes an SPF record in the Domain Name System (DNS) (opens in a new tab) listing the hosts allowed to use that domain, and receivers test the sending server against it (RFC 7208 (opens in a new tab)).
- DKIM signs the message. A DKIM signature ties a domain, its
d=value, to a hash of some or all of the message; verifying it shows the signed content has not changed since signing (RFC 6376 (opens in a new tab)).
DMARC does not use their pass or fail alone. It uses the domain each one authenticated: the d= domain of a valid DKIM signature, and the MAIL FROM domain that SPF validated (RFC 9989 section 4.4 (opens in a new tab)). A message passes when at least one of those domains is aligned with the From domain, and fails when none is (section 5.3 (opens in a new tab)).
Aligned does not have to mean identical. With relaxed alignment, the default, the two domains share the same Organizational Domain, in practice the root domain, so a subdomain aligns with it; with strict alignment they must be identical (section 3.2.10 (opens in a new tab), Microsoft (opens in a new tab)).
This is how SPF and DKIM can each show pass while DMARC shows fail. Any domain owner can publish an SPF record for its own domain and get an SPF pass, and a message can carry a valid DKIM signature from any domain, which is why DMARC requires alignment.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.
How to read the Authentication-Results header
Message headers carry the results of the SPF, DKIM and DMARC checks (Google Workspace (opens in a new tab)). For a message sent from your domain, you can paste its headers into Google Admin Toolbox's Messageheader tool. In Microsoft 365, open the message headers and find the Authentication-Results header that Microsoft 365 added (Microsoft (opens in a new tab)).
Microsoft's example is a message where SPF and DKIM both pass, but DMARC fails because neither domain aligns with the From domain. Here it is with the domain names replaced by example ones:
Authentication-Results: spf=pass (sender IP is 198.51.100.10)
smtp.mailfrom=bounces.example.net; dkim=pass (signature was verified)
header.d=example.net; dmarc=fail action=oreject
header.from=example.com;compauth=fail reason=000
Three fields show which domain each check used:
| Field | What it holds |
|---|---|
smtp.mailfrom= |
The MAIL FROM domain that SPF checked, for SPF alignment |
header.d= |
The DKIM signing domain, for DKIM alignment |
header.from= |
The From domain; DMARC passes if either the SPF or the DKIM domain aligns with it |
In the example, bounces.example.net and example.net are in a different organizational domain from example.com, so both alignment checks fail and DMARC fails.
In Microsoft 365, the action= value after dmarc=fail shows the policy the sender published and what Microsoft 365 did:
action=none: the sender publishedp=none, and no DMARC-specific action was taken; other filtering still applies.action=quarantine: the sender publishedp=quarantine, and the message was quarantined or junked.action=oreject: the sender publishedp=reject, and the message was rejected.
Why DMARC fails
A service sends with its own domain
Mail that authorized third parties send for you might not be aligned, which also prevents a pass (RFC 9989 section 7.3 (opens in a new tab)). Microsoft (opens in a new tab) gives the symptom: SPF passes for the service's domain but DMARC fails, because the MAIL FROM uses the service's domain and the service does not sign DKIM with yours. In a related case DKIM passes but DMARC still fails, because the DKIM d= value is the service's domain and doesn't align with your From domain.
Forwarding and mailing lists
Forwarding often breaks SPF: at the final mailbox, the forwarding server's address is not one the original MAIL FROM domain authorized (RFC 9989 section 7.4 (opens in a new tab)). If the forwarder rewrites the MAIL FROM to its own domain, SPF might pass, but that domain does not align with the original From domain (RFC 7960 (opens in a new tab)). DMARC then depends on DKIM.
An aligned DKIM signature can survive forwarding when the signed headers and body stay unchanged: an alias that preserves the content and makes no significant header changes may leave DKIM signatures valid, while modifying the content invalidates most DKIM signatures. Microsoft (opens in a new tab) names mailing lists and transport rules that change the body after signing as a cause of DKIM failure. When neither SPF nor DKIM passes in alignment, DMARC fails.
Mail sent through mailing lists with an unmodified From line is frequently rejected under a p=reject policy, and mailing list software has adopted workarounds to make the From line DMARC aligned. Yahoo (opens in a new tab) asks senders who forward email to implement ARC (Authenticated Received Chain), and Microsoft suggests trusted ARC sealers at the destination.
A server missing from SPF, or a changed message
Google's troubleshooting guide (opens in a new tab) lists two more causes: the message was sent by a server that isn't in your SPF record, or it was modified in transit or after the DKIM signature was added. Check that your SPF record includes every IP address and domain allowed to send mail for your domain.
Strict alignment
With aspf=s in your DMARC record, SPF alignment needs an exact match, so it fails when the MAIL FROM domain is a subdomain of the From domain, such as bounces.example.com for example.com. DMARC can still pass through aligned DKIM, because one aligned check is enough. Microsoft's fix is to change to aspf=r (relaxed) or make the From address match the subdomain. Google notes that strict alignment increases the likelihood that messages are rejected or sent to spam, and nearly all domain owners have found relaxed alignment sufficient (RFC 9989 section 4.4 (opens in a new tab)).
How to fix it
1. Find the sender that fails
For a single message, compare smtp.mailfrom= and header.d= with header.from= in its header. For a wider view, DMARC aggregate reports can reveal mail streams that use your domain but don't pass DMARC (RFC 9989 section 5.1.6 (opens in a new tab)). They come only from receivers that send them; some opt out (section 5.3 (opens in a new tab)).
2. Sign DKIM with your domain
For DKIM to count, your mail must carry a DKIM signing domain aligned with your From domain (RFC 9989 section 5.1.2 (opens in a new tab)). For a third-party service, that means configuring custom DKIM signing at the service using your domain (Microsoft (opens in a new tab)). Domains that publish p=reject must not rely on SPF alone and must apply valid DKIM signatures (section 7.4 (opens in a new tab)).
3. Or align the MAIL FROM, and publish SPF on it
For SPF to count, your mail must use a MAIL FROM domain aligned with your From domain (RFC 9989 section 5.1.1 (opens in a new tab)). Set the service's envelope sender to your domain, as Google (opens in a new tab) asks, or to a subdomain of it, which Microsoft also allows; then publish the service's SPF record on that exact MAIL FROM domain. Receivers look up SPF at the domain of the MAIL FROM address (RFC 7208 section 4 (opens in a new tab)), and each subdomain used for email needs its own SPF record, so a record on example.com does not cover bounces.example.com. The SPF record generator builds a record from the services that send email for your domain.
4. Use a dedicated subdomain if the service supports it
If the service can sign DKIM with a subdomain of yours, send from an address on that subdomain, publish a separate DMARC record for the subdomain, and have the service sign DKIM with the same subdomain.
5. Keep relaxed alignment
Relaxed alignment, the default, accepts a subdomain of your domain, for example mail.example.com for example.com; strict requires an exact match, and most domains keep relaxed (DMARC record generator).
What happens to mail that fails
Each receiver decides. The final handling of any message is left to the receiver's own policies, and a receiver may accept mail that fails DMARC even when the policy is p=reject (RFC 9989 section 5.4 (opens in a new tab)).
For inbound mail with Honor DMARC record policy on, Microsoft 365 (opens in a new tab) takes no DMARC-specific action at p=none, though other filtering still applies. It sends p=quarantine failures to the Junk Email folder (configurable to quarantine) and rejects p=reject failures during SMTP with 550 5.7.1.
Gmail may mark unauthenticated messages as spam or reject them with a 5.7.26 error (Google's sender guidelines (opens in a new tab)). When a message from your domain fails DMARC, the sender might get this in the bounce (Google Workspace (opens in a new tab)): "Unauthenticated email from domain-name is not accepted due to domain's DMARC policy." If your policy is p=none and messages still go to spam, the cause might be something other than your DMARC record.
Don't tighten the policy while legitimate mail still fails: legitimate streams that fail alignment must be fixed before any move to enforcement (RFC 9989 section 5.1.6 (opens in a new tab)). The DMARC policy not enabled guide covers the order for moving from p=none to quarantine or reject.
Check your records
After you change a sender's setup, DemiSignal's check reads the public DNS records of the domain you enter and checks your SPF, DKIM and DMARC records, with no account needed. A DNS finding shows how your domain is set up; it does not show where a particular message landed. To confirm the fix for one sender, send a new test message through it and read its header.
Sources
- RFC 9989 (RFC Editor information page) (opens in a new tab)
- RFC 9989 section 3.2.10: Identifier Alignment (opens in a new tab)
- RFC 9989 section 4.4: Identifier Alignment Explained (opens in a new tab)
- RFC 9989 section 5.1.1: Publish an SPF Record for an Aligned Domain (opens in a new tab)
- RFC 9989 section 5.1.2: Configure Sending System for DKIM Signing Using an Aligned Domain (opens in a new tab)
- RFC 9989 section 5.1.6: Remediate Unaligned or Unauthenticated Mail Streams (opens in a new tab)
- RFC 9989 section 5.3: Mail Receiver Actions (opens in a new tab)
- RFC 9989 section 5.4: Policy Enforcement Considerations (opens in a new tab)
- RFC 9989 section 7.3: Interoperability Issues (opens in a new tab)
- RFC 9989 section 7.4: Interoperability Considerations (opens in a new tab)
- RFC 7208: Sender Policy Framework (SPF), section 1 (opens in a new tab)
- RFC 7208 section 4: The check_host() Function (opens in a new tab)
- RFC 6376: DomainKeys Identified Mail (DKIM) Signatures, section 1 (opens in a new tab)
- RFC 7960: Interoperability Issues between DMARC and Indirect Email Flows (opens in a new tab)
- Google: Email sender guidelines (opens in a new tab)
- Google Workspace: Troubleshoot DMARC issues (opens in a new tab)
- Google Workspace: Set up DMARC (opens in a new tab)
- Google Workspace: About TXT records (opens in a new tab)
- Microsoft: Set up DMARC to validate email in Microsoft 365 (opens in a new tab)
- Microsoft: Troubleshoot email authentication in Microsoft 365 (opens in a new tab)
- Yahoo: Sender best practices (opens in a new tab)
- DemiSignal: SPF, DKIM and DMARC check
- DemiSignal: SPF record generator
- DemiSignal: DMARC record generator
- DemiSignal: DMARC policy not enabled
Tools for this
-
SPF, DKIM and DMARC check
Check the email records a domain publishes today and see what to fix first.
-
SPF record generator
Build an SPF record for the services that send your email.
-
DMARC record generator
Build a DMARC record step by step, from monitoring to reject.
Frequently asked questions
What does dmarc=fail mean?
A DMARC policy applies to the domain in the From address, but neither SPF nor DKIM passed for a domain aligned with it. One aligned pass from either is enough for DMARC to pass.
Why does DMARC fail when SPF and DKIM both pass?
The domains that passed are not aligned with the From domain, for example when a service uses its own domain for the MAIL FROM and signs DKIM with its own domain.
Does forwarding make DMARC fail?
Forwarding often breaks SPF. Rewriting the MAIL FROM may restore SPF without aligning it with the original From domain. DMARC can still pass if an aligned DKIM signature survives; changes to signed headers or the body can break that signature.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.