Prompt
How do I debug SPF DKIM DMARC failures?
Latest observation
Here’s a practical way to debug SPF, DKIM, and DMARC failures without getting lost.
1) Start with the symptom
Identify where it failed:
- In your mail provider’s logs
- In the recipient’s bounce or message headers
- In tools like Gmail “Show original,” Microsoft headers, etc.
Look for:
- SPF result: pass / fail / softfail / neutral / permerror
- DKIM result: pass / fail / temperror / permerror
- DMARC result: pass / fail
- Alignment: whether the “From” domain matches SPF/DKIM authenticated domains
2) Check SPF first
SPF verifies whether the sending server is allowed to send for the envelope sender domain.
Common SPF failure causes
- Sending from an IP not included in the SPF record
- Too many DNS lookups
- Multiple SPF records for the same domain
- Using the wrong domain in the envelope sender / return-path
- Forwarders or mailing lists breaking SPF
What to inspect
Run:
dig TXT yourdomain.com
Look for a record like:
v=spf1 include:_spf.google.com ip4:203.0.113.10 -all
SPF debugging tips
- Ensure there is only one SPF record
- Check for:
include:chains that expand too muchmx,a,ptrcausing unexpected results~allvs-all
- Verify the actual sending IP matches the record
- If using a third-party sender, confirm you added their SPF include exactly as documented
3) Check DKIM next
DKIM signs the message with a private key; receivers verify it using the public key in DNS.
Common DKIM failure causes
- Signature broken by message modification
- Wrong selector or domain
- Missing/wrong public key in DNS
- Key rotation mismatch
- Mailing list footers or relays altering headers/body
- Body canonicalization issues
What to inspect
Look at message headers for:
DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=selector1; ...
Then check DNS:
dig TXT selector1._domainkey.example.com
DKIM debugging tips
- Confirm the selector matches DNS
- Confirm
d=is the domain you expect - If signing is handled by a provider, make sure DKIM is enabled there
- Use a full copy of the message headers to verify the signature against the exact message received
4) Check DMARC alignment
DMARC passes if:
- SPF passes and aligns, or
- DKIM passes and aligns
Alignment means the authenticated domain must match the visible From: domain, either exactly or under relaxed alignment rules.
Common DMARC failure causes
- SPF passes for a different domain than the visible
From - DKIM passes, but
d=is not aligned withFrom - Both SPF and DKIM fail
- Subdomain policy issues
What to inspect
Check the DMARC record:
dig TXT _dmarc.example.com
Example:
v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com
Also verify:
From: user@example.com- SPF authenticated domain is
example.comor aligned subdomain - DKIM
d=example.comor aligned subdomain
5) Use the full headers
The fastest way to troubleshoot is with the raw message headers.
Look for lines like:
Authentication-Results: ...
Received-SPF: ...
DKIM-Signature: ...
Examples:
Authentication-Results: mx.google.com;
spf=pass smtp.mailfrom=bounce.example.com;
dkim=pass header.d=example.com;
dmarc=pass header.from=example.com
If failing:
spf=fail smtp.mailfrom=bounce.example.net;
dkim=pass header.d=example.com;
dmarc=fail header.from=example.com
That tells you SPF passed/failed for one domain, DKIM for another, and whether alignment is broken.
6) Test with external tools
Useful tools:
- MXToolbox
- dmarcian
- Google Admin Toolbox
- mail-tester.com
- Kitterman SPF validator
openssl/dig/ header analysis
Send a test email to a mailbox you control and inspect the headers.
7) Common real-world causes
- Sending mail through a marketing platform without updating SPF/DKIM
- Forwarding through a relay that changes the envelope sender
- A/B testing platforms changing From or reply-to domains
- DNS record syntax errors
- Oversized SPF due to too many includes
- DMARC policy too strict before SPF/DKIM are set up
8) A quick debugging workflow
- Get the raw headers
- Note the visible From domain
- Check SPF result and
smtp.mailfrom - Check DKIM result and
header.d - Check DMARC result and whether SPF/DKIM align with
From - Validate DNS records with
dig - Fix the domain used by your sender or the DNS records
9) If you want, send me:
- The Authentication-Results header
- Your SPF record
- Your DKIM-Signature header
- Your DMARC record
…and I can help you pinpoint the exact failure.