DIAGNOSTIC PLAYBOOK
An unfamiliar IP in DMARC reports: identify the service
An unfamiliar source IP in a DMARC report is an investigation lead, not automatic proof of spoofing. Shared platforms, relays and forwarding services may send legitimate traffic from addresses you do not recognize.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Group the source by volume, authentication domains, selectors and policy outcomes.
- Compare those identities with your approved sender inventory and recent vendor changes.
- Ask the likely service owner for a matching message or sending log before marking the traffic legitimate or abusive.
What this looks like
ILLUSTRATIVE EXAMPLE
A customer support platform changes its outbound range. The IP is new to your report, but the aligned signature and internal sending logs connect it to an approved workflow.
A mistake to avoid
Reverse DNS and IP ownership alone do not prove a message came from your account on a shared service.
Keep the result in context
DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.