Troubleshooting
Diagnose failing sources, missing reports and odd results.
- No reports yet? What to checkAn empty DMARC dashboard is usually just the daily reporting cycle — but not always. Work through the causes in order, from delay to typos to low volume.
- Why sources show as UnknownUnknown means no provider fingerprint matched — not that the source is malicious. How to expand the group, judge each IP, and tell benign from spoofing.
- Why SPF fails on forwarded mailForwarded mail always fails SPF — the forwarder delivers from its own server. Why DKIM survives, why DMARC still passes, and where mailing lists fit.
- DMARC fails but mail still deliveredEnforcement is the receiver's decision. Why failing mail still lands — p=none, pct sampling, forwarding overrides — and how to read the disposition field.
- DMARC pass and fail, explainedWhat makes a message pass DMARC, every way it can fail, and how DMARCmetric's verdict labels — pass, mixed, would reject — map onto your real traffic.
- DMARC policy not enabled: what it meansDMARC policy not enabled means your record exists but p= is none or missing, so nothing is blocked. Find which of three states you are in, and fix it.
- Common causes of DMARC failureCommon causes of DMARC failure and sending email breaches — eight of them, what each looks like in your aggregate reports, and the fix for each one.
- Why DKIM failsDKIM either verifies or it doesn't — there is no partial credit. The handful of causes behind almost every failure, and how to tell them apart from reports.
- SPF: too many DNS lookups (PermError)SPF allows ten DNS-querying mechanisms. Cross that line and the record fails everywhere at once — how to count yours, and the four ways to get back under it.
- SPF softfail vs hardfail (~all vs -all)What receivers actually do with ~all and -all, why the difference matters less once DMARC enforces, and which one to publish at each stage of a rollout.
- Two SPF records on one domainA domain may publish exactly one SPF record. A second one is a PermError that voids both — how to spot it and how to merge them without losing a sender.
- 550 5.7.26 — unauthenticated emailGmail rejects mail that isn't authenticated. What the 5.7.26 bounce is actually telling you, why it names your domain, and the order to fix it in.
- DKIM key length and rotationWhy 1024-bit keys still exist, when 2048 breaks a DNS record, and how to rotate a DKIM key without a gap where mail fails verification.
Still stuck?
We answer every message — usually within one business day.
Email [email protected]