Prompt

My SPF DKIM and DMARC setup keeps failing

Technology / API Platforms1 observationLast seen Oct 5, 2026

Latest observation

Oct 5, 2026OpenAI APIWeb search: off

I can help troubleshoot it. “SPF, DKIM, and DMARC keep failing” usually means one of these is off: the DNS records, the sending service, alignment, or the mail is being changed after signing.

First, tell me:

  1. What email provider are you sending from?
    (Google Workspace, Microsoft 365, SendGrid, Mailchimp, custom server, etc.)
  2. What exactly is failing?
    • SPF fail
    • DKIM fail
    • DMARC fail
    • or “passes individually but DMARC fails”
  3. Paste the headers from a message that failed authentication
    Specifically, look for:
    • Authentication-Results:
    • Received-SPF:
    • DKIM-Signature:
    • From:
  4. Paste your DNS records for:
    • SPF TXT record
    • DKIM public key record
    • DMARC TXT record

You can redact domains/IPs if needed, but keep the structure.

Common causes

SPF fails

  • You have more than one SPF record for the same domain.
  • The sending IP/service is not included in the SPF include: or ip4/ip6.
  • SPF hits the 10 DNS lookup limit.
  • You’re sending from a service that uses a different envelope-from / return-path domain.
  • The mail is sent through a relay not authorized in SPF.

DKIM fails

  • Wrong selector in DNS.
  • DKIM key copied incorrectly or missing characters.
  • Mail is being altered after signing:
    • disclaimers added
    • subject rewritten
    • line wrapping changed
    • footer inserted
  • The signing server is not the one you expect.

DMARC fails

DMARC passes only if SPF or DKIM passes AND aligns with the visible From domain.

So DMARC can fail even if:

  • SPF passes but uses a different domain than From:
  • DKIM passes but is signed with a different domain than From:

Quick checks you can do now

  • Make sure there is only one SPF record per domain.
  • Ensure your DMARC policy starts with p=none while testing.
  • Confirm DKIM is enabled on the actual sending service.
  • Check whether the From: domain matches the SPF/DKIM authenticated domain.
  • Verify no mail gateway is modifying outgoing messages.

If you want, paste this and I’ll interpret it

Headers:

Authentication-Results: ...
Received-SPF: ...
DKIM-Signature: ...
From: ...

DNS records:

example.com TXT "v=spf1 ..."
selector._domainkey.example.com TXT "v=DKIM1; k=rsa; p=..."
_dmarc.example.com TXT "v=DMARC1; p=none; ..."

If you share the header output, I can usually tell you exactly what’s wrong.

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as dotdotPR. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.