Prompt

How do I debug SPF DKIM DMARC failures?

Technology / API Platforms1 observationLast seen Oct 5, 2026

Latest observation

Oct 5, 2026OpenAI APIWeb search: off

Here’s a practical way to debug SPF, DKIM, and DMARC failures without getting lost.

1) Start with the symptom

Identify where it failed:

  • In your mail provider’s logs
  • In the recipient’s bounce or message headers
  • In tools like Gmail “Show original,” Microsoft headers, etc.

Look for:

  • SPF result: pass / fail / softfail / neutral / permerror
  • DKIM result: pass / fail / temperror / permerror
  • DMARC result: pass / fail
  • Alignment: whether the “From” domain matches SPF/DKIM authenticated domains

2) Check SPF first

SPF verifies whether the sending server is allowed to send for the envelope sender domain.

Common SPF failure causes

  • Sending from an IP not included in the SPF record
  • Too many DNS lookups
  • Multiple SPF records for the same domain
  • Using the wrong domain in the envelope sender / return-path
  • Forwarders or mailing lists breaking SPF

What to inspect

Run:

dig TXT yourdomain.com

Look for a record like:

v=spf1 include:_spf.google.com ip4:203.0.113.10 -all

SPF debugging tips

  • Ensure there is only one SPF record
  • Check for:
    • include: chains that expand too much
    • mx, a, ptr causing unexpected results
    • ~all vs -all
  • Verify the actual sending IP matches the record
  • If using a third-party sender, confirm you added their SPF include exactly as documented

3) Check DKIM next

DKIM signs the message with a private key; receivers verify it using the public key in DNS.

Common DKIM failure causes

  • Signature broken by message modification
  • Wrong selector or domain
  • Missing/wrong public key in DNS
  • Key rotation mismatch
  • Mailing list footers or relays altering headers/body
  • Body canonicalization issues

What to inspect

Look at message headers for:

DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=selector1; ...

Then check DNS:

dig TXT selector1._domainkey.example.com

DKIM debugging tips

  • Confirm the selector matches DNS
  • Confirm d= is the domain you expect
  • If signing is handled by a provider, make sure DKIM is enabled there
  • Use a full copy of the message headers to verify the signature against the exact message received

4) Check DMARC alignment

DMARC passes if:

  • SPF passes and aligns, or
  • DKIM passes and aligns

Alignment means the authenticated domain must match the visible From: domain, either exactly or under relaxed alignment rules.

Common DMARC failure causes

  • SPF passes for a different domain than the visible From
  • DKIM passes, but d= is not aligned with From
  • Both SPF and DKIM fail
  • Subdomain policy issues

What to inspect

Check the DMARC record:

dig TXT _dmarc.example.com

Example:

v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com

Also verify:

  • From: user@example.com
  • SPF authenticated domain is example.com or aligned subdomain
  • DKIM d=example.com or aligned subdomain

5) Use the full headers

The fastest way to troubleshoot is with the raw message headers.

Look for lines like:

Authentication-Results: ...
Received-SPF: ...
DKIM-Signature: ...

Examples:

Authentication-Results: mx.google.com;
  spf=pass smtp.mailfrom=bounce.example.com;
  dkim=pass header.d=example.com;
  dmarc=pass header.from=example.com

If failing:

spf=fail smtp.mailfrom=bounce.example.net;
dkim=pass header.d=example.com;
dmarc=fail header.from=example.com

That tells you SPF passed/failed for one domain, DKIM for another, and whether alignment is broken.


6) Test with external tools

Useful tools:

  • MXToolbox
  • dmarcian
  • Google Admin Toolbox
  • mail-tester.com
  • Kitterman SPF validator
  • openssl / dig / header analysis

Send a test email to a mailbox you control and inspect the headers.


7) Common real-world causes

  • Sending mail through a marketing platform without updating SPF/DKIM
  • Forwarding through a relay that changes the envelope sender
  • A/B testing platforms changing From or reply-to domains
  • DNS record syntax errors
  • Oversized SPF due to too many includes
  • DMARC policy too strict before SPF/DKIM are set up

8) A quick debugging workflow

  1. Get the raw headers
  2. Note the visible From domain
  3. Check SPF result and smtp.mailfrom
  4. Check DKIM result and header.d
  5. Check DMARC result and whether SPF/DKIM align with From
  6. Validate DNS records with dig
  7. Fix the domain used by your sender or the DNS records

9) If you want, send me:

  • The Authentication-Results header
  • Your SPF record
  • Your DKIM-Signature header
  • Your DMARC record

…and I can help you pinpoint the exact failure.

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as Circuit. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.