"dmarc=fail" in email headers: what it means and how to fix it
What's happening: DMARC passes only when SPF or DKIM passes and uses the same domain as your visible From address (alignment). The classic failure: a newsletter, CRM or invoicing tool sends as you@yourdomain.com but signs DKIM with its own domain and uses its own bounce address, so both checks pass for their domain and neither aligns with yours.
How to fix it
- Open the failing message's headers (Gmail: Show original) and note which service sent it.
- In that service, set up custom DKIM / domain authentication for your domain (usually 2-3 CNAME or TXT records). This is the fix in most cases.
- If the tool supports a custom return path or bounce domain, set that up too so SPF aligns as well.
- Keep DMARC at
p=noneuntil every legitimate sender passes, then move top=quarantine.
Not sure which record is wrong? Check your domain free: it shows which of SPF, DKIM and DMARC is failing, in 5 seconds, no signup.