Common causes
- The sending server or service (website host, SMTP relay, newsletter tool, CRM) is not included in the domain's SPF record
- DKIM is not enabled, or the signature uses the provider's domain, so DMARC alignment fails
- A website contact form sends with From: the visitor's address (e.g. a Gmail user) through your host, which fails that domain's DMARC
- More than one SPF record, or more than 10 DNS lookups in SPF, causing a permerror
- Email is forwarded through a server that breaks SPF and modifies the message (breaking DKIM)
- DNS changes after a migration left SPF pointing at the old host
How to fix it
- Read the bounce headers. Open the full bounce or the Authentication-Results header of a delivered test message. It shows spf=fail/pass, dkim=fail/pass and dmarc=fail with the domains checked.
- List every service that sends as your domain. Include your mailbox provider, the web server (WordPress/PHP mail), transactional email services and marketing tools. Each must be in SPF or sign with DKIM for your domain.
- Fix the SPF record. Keep exactly one TXT record starting with v=spf1 on the domain and add each sender's include or IP, ending with ~all or -all. Stay under 10 DNS lookups.
- Enable DKIM with your domain. Turn on DKIM in your provider (cPanel Email Deliverability, Google Workspace, Microsoft 365, your SMTP service) and publish the CNAME/TXT records it gives you, so mail is signed with d=yourdomain.
- Fix contact form senders. Send form emails From: an address on your own domain (e.g. [email protected]) and put the visitor's address in Reply-To. Send via authenticated SMTP rather than PHP mail().
- Publish or adjust DMARC. Start with v=DMARC1; p=none; rua=mailto:[email protected] to collect reports, and move to quarantine/reject once all legitimate sources pass.
- Re-test. Send to a Gmail address, use 'Show original' and confirm SPF, DKIM and DMARC all show PASS before resending to the rejecting recipient.
DNS TXT records (example)
; SPF - one record only
example.com. TXT "v=spf1 include:_spf.google.com include:spf.mailprovider.example ip4:203.0.113.10 ~all"
; DMARC - start in monitoring mode
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:[email protected]" How to stop it happening again
- Add every new email-sending service to SPF and set up its DKIM before going live
- Never send from addresses on domains you do not control
- Review DMARC aggregate reports monthly to catch unknown senders