DIAGNOSTIC PLAYBOOK

A subdomain behaves differently under DMARC

A subdomain may publish its own DMARC policy rather than using the organizational domain's applicable fallback. Look up the actual visible From domain before assuming every stream shares the same policy.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Identify the exact From domain in the affected messages.
  2. Check its DMARC record first, then evaluate the relevant organizational-domain policy and subdomain setting if needed.
  3. Compare intended policy ownership with the effective record and verify new messages after an approved change.

What this looks like

ILLUSTRATIVE EXAMPLE

The root requests rejection, while a newsletter subdomain has its own monitoring policy. The two streams can legitimately request different treatment.

A mistake to avoid

A parent policy edit may not affect a subdomain that publishes its own record. Inventory those exceptions during enforcement reviews.

Keep the result in context

DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.