DIAGNOSTIC PLAYBOOK

Why a reject policy can show disposition none

The policy requested by a domain and the disposition reported for a message are separate fields. A receiver may accept passing traffic or apply local handling that differs from the requested failure policy.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Read the report's authentication and alignment results alongside disposition.
  2. Check for a receiver-reported override reason, forwarding context or an applicable policy scope difference.
  3. Use a sample message and receiving logs when available to confirm what happened after acceptance.

What this looks like

ILLUSTRATIVE EXAMPLE

A domain requests reject, but an aligned message passes DMARC and is reported with disposition none. No rejection was required for that passing message.

A mistake to avoid

Disposition none is not an inbox-placement report. It also should not be read as proof that the published policy was ignored.

Keep the result in context

DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.