Common causes of DMARC failure
Third-party platforms are a frequent source of legitimate DMARC failures when they send on behalf of a business without the expected SPF authorisation, DKIM signature or domain alignment.
- SPF passes for a different domain that does not align with the visible From domain.
- A DKIM signature is missing, invalid or uses a signing domain that does not align.
- Forwarding changes the delivery path and SPF no longer passes for the original sender.
- A sending service was added without being included in the organisation's email-authentication design.
- The message genuinely came from an unauthorised source impersonating the domain.
