DMARC Analyzer 2.0 - Sources Failing DMARC

This article contains information on why a source is marked as failed in DMARC, explaining causes like misaligned SPF/DKIM or malicious activity, and steps to investigate and resolve issues for valid or unrecognized sources.

Why is a source marked as failed?

A source marked as failed means that emails from the source are not DMARC compliant because SPF and DKIM were invalid. This can mean two things:

  • This source failed the DMARC checks because DKIM and or SPF were not set up correctly (misaligned).
  • The source failed the DMARC checks because malicious emails were sent on behalf of your domain.

Why is a source marked as failed?

It is important to investigate all sources that appear in the failed section to identify the sources as valid or as malicious. If you recognize a source as legitimate, you can set up and align SPF and/or DKIM correctly. Unrecognized sources require investigation because the source might try to send malicious emails on behalf of your domain.

The steps that you can take to investigate the source:

  1. Do I recognize the source as a partner of my company?
  2. Search on Google what kind of source this is.
  3. Does the source appear on RBL blacklist websites?
  4. Check the forensic reports to see what kind of emails are sent by the source.
  5. If the source is valid, search for documentation to set up DMARC correctly
  6. Contact the source.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.