DIAGNOSTIC PLAYBOOK

External DMARC reports: verify destination authorization

Sending DMARC aggregate reports to another domain can require DNS authorization by the report destination. A valid rua address alone does not show that this external reporting relationship is authorized.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Compare the policy domain with the reporting destination's domain.
  2. Check the destination's required authorization name and TXT response using its documented setup instructions.
  3. Confirm the reporting service has activated your domain and allow for a complete reporting cycle.

What this looks like

ILLUSTRATIVE EXAMPLE

A policy points to a new analysis service before that service has authorized reports for the domain. Receivers may decline to send reports to it.

A mistake to avoid

The authorization lives with the destination domain. Do not try to repair it by publishing an unrelated TXT record only in your own zone.

Keep the result in context

DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.