Moving to enforcement Step 9 of 35
Identify your sending sources
Between the first report and day 14, work through the servers sending as your domain. Fix the ones that are yours and leave the rest to the policy.
Updated
Moving to a stricter DMARC policy is safe once every legitimate sender of your mail passes DMARC. The first two weeks are for finding out who those senders are. Most domains have more than their owners expect: the mail platform, plus a CRM, a helpdesk, an invoicing system, a website contact form, a scanner in the office.
Open the Sources tab
Open the domain and choose Sources. Every server that sent mail as the domain in the window (7 days, 30 days or 90 days) is listed in one of four groups:
| Group | What it means |
|---|---|
| Compliant | Passes DMARC: SPF or DKIM aligned with your domain. At least 95% of its mail passes. Nothing to do. |
| Known sender, failing | A service the library recognises that isn’t aligned yet. Each has a fix guide. |
| Forwarded | Your mail relayed by a forwarder, mailing list or filtering gateway. Expected to fail SPF; DKIM survives when untouched. |
| Unknown or threat | Not recognised and failing. Either a sender you haven’t set up, or someone spoofing your domain. |

Each source is listed by its IP address, with its reverse DNS name under it, the sender when we recognise it, its messages, its DMARC pass rate, and how many messages were DKIM aligned and SPF aligned. Download sources (CSV) saves the list.
How senders are recognised
The Sender library (in the left sidebar under the product name) lists the services we recognise, with the SPF include and the DKIM steps for each. A source is matched to one by evidence a third party can’t fake for your domain: the server’s reverse DNS name, and the domains it signs or sends with in your reports. Never by the network alone: a large provider’s network also carries its cloud customers’ servers.

Look at a source
Choose a source’s address to open it. The page shows its group, its pass rate, its network and when it was first and last seen; for a recognised sender, how to make it pass; then Authentication results by receiver, and the Raw records exactly as reported.

The pattern usually tells you what an unrecognised source is:
- Steady volume on most days is a system: something of yours, or something sending on your behalf, that hasn’t been set up yet.
- A single burst, then nothing, from addresses you don’t recognise, is almost always someone spoofing the domain. That’s what DMARC enforcement is for, and there’s nothing to fix.
Fix the ones that are yours
For each legitimate sender that fails, set it up to send as your domain in the service’s own settings. The source page gives the steps for a recognised sender, with a link to its documentation.
- DKIM is the better fix where the service supports it: it publishes a key under your domain (usually one or two CNAME or TXT records it gives you) and signs your mail with it. DKIM survives forwarding.
- SPF, adding the service’s
include:to your SPF record, only aligns when the service sends with your domain as the envelope sender, and fails once the mail is forwarded. Watch the ten-lookup limit as you add services.
Why SPF and DKIM can pass while DMARC still fails covers the alignment rules.
The change shows in the reports from the next day. A source you’ve fixed moves to Compliant; one that keeps failing stays in front of you, and if it fails on three or more days with meaningful volume, the adviser names it as a blocker. See the 14-day review.
Subdomains
Mail whose From address is a subdomain, such as news.example.org, is covered
by the parent domain’s policy unless the subdomain publishes its own. The
domain’s Overview lists them under Subdomains seen, with their messages
and pass rate.
Next
Stuck? Reply to any email DMARCLoop sends, or contact us — a person reads it.