E-Mail-Authentifizierung & DMARC6 min read2 sections

Troubleshooting Guide

Common DMARC, SPF, and DKIM problems and how to diagnose and fix them.

01

Common Authentication Failures

1. "SPF pass but DMARC fail"

Cause: SPF passed for the Return-Path domain, but that domain doesn't align with the From: domain.

Fix: Configure the sending service to use a custom Return-Path that matches your From: domain (or a subdomain of it in relaxed mode).

2. "DKIM pass but DMARC fail"

Cause: DKIM passed for the signing domain (d=), but that domain doesn't align with the From: domain.

Fix: Configure the sending service to sign with your domain: d=yourdomain.com instead of d=service.com.

3. "Both SPF and DKIM fail"

Possible causes:

  • Unauthorized sender (Spoofing) — this is what DMARC is designed to catch
  • Legitimate sender not configured in SPF and without DKIM
  • Email forwarding broke both SPF (new sending IP) and DKIM (body modified)

4. "SPF permerror / temperror"

Cause: SPF record has syntax errors or exceeds the 10-lookup limit.

Fix: Validate your SPF record, reduce DNS lookups (use ip4/ip6 instead of include where possible), and check for multiple SPF records.

5. "High fail rate from mailing lists"

Cause: Mailing lists (Google Groups, Mailman, etc.) rewrite headers, breaking DKIM, and forward from their own IPs, breaking SPF.

Fix: This is a known limitation. Consider using ARC (Authenticated Received Chain) or accepting that mailing list emails will fail DMARC. Some lists now support ARC to preserve authentication through forwarding.

6. "Reports show disposition=none even with p=reject"

Cause: The disposition field shows what the receiver actually did, not what your policy says. Some receivers apply local overrides (e.g., based on reputation). Also, pct < 100 means only a percentage of failing emails get the policy applied.

02

Debugging Checklist

When investigating a DMARC failure, follow this systematic approach:

  1. Identify the Source IP — Who sent the email? Use reverse DNS and WHOIS.
  2. Check if it's a legitimate sender — Is this IP from a service you use?
  3. Check SPF:
    • Is the sending service included in your SPF record?
    • Is the Return-Path domain aligned with your From: domain?
    • Are you under the 10-lookup limit?
  4. Check DKIM:
    • Is the sending service signing with your domain?
    • Is the DKIM Public Key published in DNS?
    • Was the email body modified in transit?
  5. Check DMARC Alignment:
    • Does the authenticated domain (SPF/DKIM) match the From: domain?
    • Are you using Relaxed or Strict Alignment?
  6. Test: Send a test email and check the headers for authentication results.