DMARC fail
Find out which of the three DMARC failure modes applies to your domain.
What you are seeing
- dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=example.com
- Policies triggered: DNS Authentication: DMARC Fail
- The sending domain does not pass DMARC verification
What it means
DMARC passes when **at least one** of SPF or DKIM both passes *and* is aligned with the domain in the visible From header. Fail means neither condition was met for that message.
Alignment is the part people miss. SPF can pass for the provider's own envelope domain and DKIM can pass with the provider's signing domain, and DMARC still fails, because neither matched your From domain.
With relaxed alignment (the default) a subdomain matches the organisational domain. With strict alignment (`aspf=s`, `adkim=s`) the domains must match exactly, which breaks many provider setups.
A gateway message such as Mimecast's "DNS Authentication: DMARC Fail" is that gateway applying the *sending* domain's published DMARC policy. The fix belongs to whoever owns the sending domain, not to the receiving gateway.
Why it happens
- SPF passes but is not aligned
- Your bulk sender uses its own MAIL FROM domain, so SPF authenticates that domain instead of yours. Fix it by configuring a custom return path or sending subdomain in the tool, so the envelope domain is yours.
- DKIM is missing, or signs with the provider's domain
- An unsigned message, or one signed as `d=provider.net`, gives DMARC nothing aligned to work with. Turn on domain authentication in the tool so it signs with `d=yourdomain.com`.
- The message was forwarded or relayed
- Forwarding breaks SPF, and a mailing list that rewrites the subject or appends a footer breaks the DKIM body hash. Aligned DKIM from the original sender is the only thing that survives both.
- Something really is spoofing you
- Not every DMARC fail is your own mail. Aggregate reports separate your senders from unknown IPs. If the failing source is not yours, the correct response is to move your policy to enforcement, not to loosen it.
How to fix it
- 1Check the domain, not the message first. Run the check above. It grades SPF, DKIM, DMARC and whether your detected senders will align, which rules out the configuration causes before you start reading headers.
- 2Read one failing message's Authentication-Results. In Gmail use Show original. The line tells you spf=, dkim= and dmarc= plus the domains each one authenticated. Compare those domains to your From domain — that comparison *is* alignment.
- 3Turn on domain authentication in every sending tool. For each tool that sends as your domain, enable its DKIM or domain-authentication flow so it signs with your domain. This fixes alignment for the long tail of tools at once.
- 4Collect aggregate reports before changing policy. Add a `rua` address and read a week of reports. They are the only source that shows every sender, not just the ones you remember. Sign in to MailVakt to get a reporting address and a plain-language weekly summary.
- 5Then move the policy up. Once reports show every legitimate source aligning, go `p=none` → `p=quarantine; pct=25` → `p=quarantine` → `p=reject`, waiting for clean reports at each step.
Questions
- SPF and DKIM both pass, so why does DMARC fail?
- Because neither is aligned. DMARC compares the domain SPF authenticated (the envelope sender) and the DKIM `d=` domain against your visible From domain. A pass on a provider-owned domain does not count.
- What does "DNS Authentication: DMARC Fail" mean in Mimecast?
- Mimecast evaluated the sending domain's DMARC and it failed, so its policy applied. If it is your own mail being blocked, fix alignment on the sending side; if it is inbound mail from a partner, their domain is misconfigured.
- Does p=none mean failures do not matter?
- p=none asks receivers to take no special action, so failing mail is still delivered and you only get reports. It satisfies the published-DMARC requirement, but it stops nothing.
- Can forwarding be fixed?
- Not by you, at the forwarder. What you can do is make sure your mail carries an aligned DKIM signature, which survives forwarding and lets DMARC pass anyway.
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“Mail from example.com is failing DMARC. Check SPF, DKIM and alignment for the domain and tell me exactly which one is broken.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.