Legitimate mail blocked after enforcement
Enforcement blocks wanted senders still failing authentication.
Problem summary
Enforcement blocks wanted senders still failing authentication.
Symptoms
- Wanted mail quarantined or rejected after p=quarantine/reject
- Sudden ticket spike after a DMARC policy change
- Reports still show failing legitimate sources
Possible causes
- Enforcement before all senders were aligned
- pct raised too quickly
- New ESP onboarded without auth
How to diagnose
- Identify failing sources from recent rua data
- Correlate with the policy/pct change timestamp
- Separate true spoofing from first-party gaps
How to fix
- Rollback: lower p= or pct immediately (example emergency): v=DMARC1; p=none; rua=mailto:dmarc@example.com
- Fix SPF/DKIM alignment for each legitimate source
- Re-advance enforcement only after clean report windows
How to verify
- Legitimate streams deliver again
- Failing first-party volume near zero in aggregates
Prevention
- Enforce with pct ramps and exit criteria
- Freeze new senders during enforcement changes
When to escalate
- Production mail is failing for a material share of recipients after remediation attempts