13 FOCUSED PLAYBOOKS

DMARC investigations

Read report evidence, separate legitimate senders from unknown traffic and investigate policy outcomes.

DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.

Run the DMARC checker
DIAGNOSTIC PLAYBOOK

DMARC passes while SPF fails: follow the DKIM result

DMARC can pass when SPF fails if a valid DKIM signature aligns with the visible From domain.

Read the playbook →
DIAGNOSTIC PLAYBOOK

SPF passes but DMARC fails: inspect the return-path domain

SPF can pass for a vendor-controlled return-path domain without aligning with your visible From domain.

Read the playbook →
DIAGNOSTIC PLAYBOOK

External DMARC reports: verify destination authorization

Sending DMARC aggregate reports to another domain can require DNS authorization by the report destination.

Read the playbook →
DIAGNOSTIC PLAYBOOK

DMARC reports stopped arriving: separate delay from breakage

Missing DMARC reports can result from delivery delays, changed reporting configuration or a lack of reportable traffic.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Duplicate DMARC reports: avoid counting traffic twice

Aggregate reports can be resent or ingested more than once.

Read the playbook →
DIAGNOSTIC PLAYBOOK

An unfamiliar IP in DMARC reports: identify the service

An unfamiliar source IP in a DMARC report is an investigation lead, not automatic proof of spoofing.

Read the playbook →
DIAGNOSTIC PLAYBOOK

A subdomain behaves differently under DMARC

A subdomain may publish its own DMARC policy rather than using the organizational domain's applicable fallback.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Strict DMARC alignment breaks a subdomain sender

Strict alignment requires an exact domain match for the relevant mechanism.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Why a reject policy can show disposition none

The policy requested by a domain and the disposition reported for a message are separate fields.

Read the playbook →
DIAGNOSTIC PLAYBOOK

DMARC reports show raw pass and policy failure

DMARC aggregate reports separate raw authentication results from policy-level aligned results.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Why DMARC forensic reports may never arrive

A ruf address does not guarantee message-level failure reports.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Protect a domain that should never send email

A non-sending domain still benefits from an explicit email policy, but first verify that no application or vendor uses it.

Read the playbook →
DIAGNOSTIC PLAYBOOK

Forwarded mail and DMARC: investigate receiver overrides

Forwarding can break SPF and sometimes DKIM, leaving receivers to apply additional local evidence.

Read the playbook →