"dmarc=fail" in email headers: what it means and how to fix it

What's happening: DMARC passes only when SPF or DKIM passes and uses the same domain as your visible From address (alignment). The classic failure: a newsletter, CRM or invoicing tool sends as you@yourdomain.com but signs DKIM with its own domain and uses its own bounce address, so both checks pass for their domain and neither aligns with yours.

How to fix it

  1. Open the failing message's headers (Gmail: Show original) and note which service sent it.
  2. In that service, set up custom DKIM / domain authentication for your domain (usually 2-3 CNAME or TXT records). This is the fix in most cases.
  3. If the tool supports a custom return path or bounce domain, set that up too so SPF aligns as well.
  4. Keep DMARC at p=none until every legitimate sender passes, then move to p=quarantine.

Not sure which record is wrong? Check your domain free: it shows which of SPF, DKIM and DMARC is failing, in 5 seconds, no signup.

Other fix guides