Moving to enforcement Step 9 of 35

Identify your sending sources

Between the first report and day 14, work through the servers sending as your domain. Fix the ones that are yours and leave the rest to the policy.

Updated

Moving to a stricter DMARC policy is safe once every legitimate sender of your mail passes DMARC. The first two weeks are for finding out who those senders are. Most domains have more than their owners expect: the mail platform, plus a CRM, a helpdesk, an invoicing system, a website contact form, a scanner in the office.

Open the Sources tab

Open the domain and choose Sources. Every server that sent mail as the domain in the window (7 days, 30 days or 90 days) is listed in one of four groups:

Group What it means
Compliant Passes DMARC: SPF or DKIM aligned with your domain. At least 95% of its mail passes. Nothing to do.
Known sender, failing A service the library recognises that isn’t aligned yet. Each has a fix guide.
Forwarded Your mail relayed by a forwarder, mailing list or filtering gateway. Expected to fail SPF; DKIM survives when untouched.
Unknown or threat Not recognised and failing. Either a sender you haven’t set up, or someone spoofing your domain.

The Sources tab for example.org, grouped

Each source is listed by its IP address, with its reverse DNS name under it, the sender when we recognise it, its messages, its DMARC pass rate, and how many messages were DKIM aligned and SPF aligned. Download sources (CSV) saves the list.

How senders are recognised

The Sender library (in the left sidebar under the product name) lists the services we recognise, with the SPF include and the DKIM steps for each. A source is matched to one by evidence a third party can’t fake for your domain: the server’s reverse DNS name, and the domains it signs or sends with in your reports. Never by the network alone: a large provider’s network also carries its cloud customers’ servers.

The Sender library

Look at a source

Choose a source’s address to open it. The page shows its group, its pass rate, its network and when it was first and last seen; for a recognised sender, how to make it pass; then Authentication results by receiver, and the Raw records exactly as reported.

A known sender failing: HubSpot sending as example.org, not aligned

The pattern usually tells you what an unrecognised source is:

  • Steady volume on most days is a system: something of yours, or something sending on your behalf, that hasn’t been set up yet.
  • A single burst, then nothing, from addresses you don’t recognise, is almost always someone spoofing the domain. That’s what DMARC enforcement is for, and there’s nothing to fix.

Fix the ones that are yours

For each legitimate sender that fails, set it up to send as your domain in the service’s own settings. The source page gives the steps for a recognised sender, with a link to its documentation.

  • DKIM is the better fix where the service supports it: it publishes a key under your domain (usually one or two CNAME or TXT records it gives you) and signs your mail with it. DKIM survives forwarding.
  • SPF, adding the service’s include: to your SPF record, only aligns when the service sends with your domain as the envelope sender, and fails once the mail is forwarded. Watch the ten-lookup limit as you add services.

Why SPF and DKIM can pass while DMARC still fails covers the alignment rules.

The change shows in the reports from the next day. A source you’ve fixed moves to Compliant; one that keeps failing stays in front of you, and if it fails on three or more days with meaningful volume, the adviser names it as a blocker. See the 14-day review.

Subdomains

Mail whose From address is a subdomain, such as news.example.org, is covered by the parent domain’s policy unless the subdomain publishes its own. The domain’s Overview lists them under Subdomains seen, with their messages and pass rate.

Next

The 14-day review: moving to p=quarantine.

Stuck? Reply to any email DMARCLoop sends, or contact us — a person reads it.