13 FOCUSED PLAYBOOKS
DMARC investigations
Read report evidence, separate legitimate senders from unknown traffic and investigate policy outcomes.
DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.
Run the DMARC checker →DMARC passes while SPF fails: follow the DKIM result
DMARC can pass when SPF fails if a valid DKIM signature aligns with the visible From domain.
Read the playbook →DIAGNOSTIC PLAYBOOKSPF passes but DMARC fails: inspect the return-path domain
SPF can pass for a vendor-controlled return-path domain without aligning with your visible From domain.
Read the playbook →DIAGNOSTIC PLAYBOOKExternal DMARC reports: verify destination authorization
Sending DMARC aggregate reports to another domain can require DNS authorization by the report destination.
Read the playbook →DIAGNOSTIC PLAYBOOKDMARC reports stopped arriving: separate delay from breakage
Missing DMARC reports can result from delivery delays, changed reporting configuration or a lack of reportable traffic.
Read the playbook →DIAGNOSTIC PLAYBOOKDuplicate DMARC reports: avoid counting traffic twice
Aggregate reports can be resent or ingested more than once.
Read the playbook →DIAGNOSTIC PLAYBOOKAn unfamiliar IP in DMARC reports: identify the service
An unfamiliar source IP in a DMARC report is an investigation lead, not automatic proof of spoofing.
Read the playbook →DIAGNOSTIC PLAYBOOKA subdomain behaves differently under DMARC
A subdomain may publish its own DMARC policy rather than using the organizational domain's applicable fallback.
Read the playbook →DIAGNOSTIC PLAYBOOKStrict DMARC alignment breaks a subdomain sender
Strict alignment requires an exact domain match for the relevant mechanism.
Read the playbook →DIAGNOSTIC PLAYBOOKWhy a reject policy can show disposition none
The policy requested by a domain and the disposition reported for a message are separate fields.
Read the playbook →DIAGNOSTIC PLAYBOOKDMARC reports show raw pass and policy failure
DMARC aggregate reports separate raw authentication results from policy-level aligned results.
Read the playbook →DIAGNOSTIC PLAYBOOKWhy DMARC forensic reports may never arrive
A ruf address does not guarantee message-level failure reports.
Read the playbook →DIAGNOSTIC PLAYBOOKProtect a domain that should never send email
A non-sending domain still benefits from an explicit email policy, but first verify that no application or vendor uses it.
Read the playbook →DIAGNOSTIC PLAYBOOKForwarded mail and DMARC: investigate receiver overrides
Forwarding can break SPF and sometimes DKIM, leaving receivers to apply additional local evidence.
Read the playbook →