Email & SMTP
Fix "DMARC Failed" Error
Diagnose and fix a DMARC alignment failure showing up in your aggregate reports or bounced mail.
The Problem
A DMARC aggregate report (or a bounce message) is showing failures — meaning messages claiming to be from your domain aren't passing the alignment checks your own DMARC policy requires, which can mean legitimate mail getting blocked or genuine spoofing slipping through unreported.
About this problem
A DMARC failure specifically means that while SPF or DKIM (or both) might technically pass, neither one is aligned with the domain shown in the visible From: address — DMARC requires that alignment specifically, not just a passing SPF or DKIM check on some unrelated domain. This confuses a lot of people who've confirmed SPF and DKIM are both "passing" individually but still see DMARC failures.
It commonly shows up when a third-party sending service uses its own domain for the technical SPF/DKIM checks while your domain appears in the visible From: address, or when DMARC was set up before SPF/DKIM alignment was fully verified.
What's Included
- Reading the DMARC aggregate report (or failure notice) to identify exactly which sending source is failing alignment
- Checking whether SPF and DKIM are passing in isolation but failing alignment specifically
- Correcting the sending configuration (or DMARC alignment mode) so the relevant check aligns with your visible From: domain
- Verifying with live test sends from each affected source that alignment now passes
- Advising on policy level (none/quarantine/reject) based on what's now confirmed passing
What's NOT Included
- Setting up SPF or DKIM from scratch if genuinely missing entirely (separate or bundled service)
- Fixing alignment for a sending service that fundamentally doesn't support using your domain for SPF or DKIM (a platform limitation, not a configuration fix)
- Ongoing interpretation of DMARC reports after this specific issue is resolved
How It Works
- Pull the relevant DMARC aggregate report (or failure sample) and identify the specific source IP and sending service involved.
- Check SPF and DKIM results individually for that source, then check each specifically against DMARC's alignment requirement to the visible From: domain.
- Determine which side is misaligned — SPF domain mismatch, DKIM domain mismatch, or both — and what the sending service actually supports.
- Reconfigure the sending service (custom return-path for SPF, custom DKIM domain/selector) to align with your domain where the platform allows it.
- If strict alignment isn't supported by that platform, consider relaxed alignment mode as a deliberate, documented trade-off rather than leaving it failing silently.
- Send live test messages from the corrected source and confirm the next aggregate report shows a clean pass.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- What's the difference between an SPF failure and a DMARC failure?
- SPF failing means the sending server isn't authorised at all. DMARC failing specifically means SPF or DKIM might be passing, but not for a domain that matches what's shown in the visible From: address — a more subtle alignment problem.
- Why does my DMARC report show failures even though SPF passes?
- SPF can pass for the technical return-path domain used by a sending service while your actual From: address shows a different domain — DMARC requires those to align, which SPF alone doesn't check.
- What is DMARC alignment and why does it matter?
- Alignment means the domain used for SPF or DKIM has to match (exactly or by organisational domain, depending on mode) the domain shown in the visible From: address — it's what stops an unrelated-but-technically-valid domain from passing DMARC on your behalf.
- Can a third-party email service cause DMARC failures I can't fix?
- Sometimes — if a platform doesn't support custom DKIM signing or a custom return-path domain for SPF, true alignment isn't possible on that platform, and the realistic options are switching settings, switching platforms, or accepting relaxed alignment.
- Should I switch my DMARC policy back to monitoring-only if I'm seeing failures?
- It depends on whether the failures are from a legitimate source you need to fix, or clear spoofing you want blocked — dropping back to monitoring-only while fixing a specific legitimate source is reasonable, but it shouldn't become permanent.
- How often do DMARC aggregate reports arrive?
- Most major providers send them roughly once a day per reporting domain, so a fix can typically be confirmed as working within a day or two of the correction going live.
- Can I ignore occasional DMARC failures from an unknown source?
- Not really — consistent unexplained failures are exactly what DMARC reporting is meant to surface, and they're worth checking rather than dismissing, since they're either spoofing or a legitimate sender you don't know is using your domain.