Prompt
My SPF DKIM and DMARC setup keeps failing
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
I can help troubleshoot it. “SPF, DKIM, and DMARC keep failing” usually means one of these is off: the DNS records, the sending service, alignment, or the mail is being changed after signing.
First, tell me:
- What email provider are you sending from?
(Google Workspace, Microsoft 365, SendGrid, Mailchimp, custom server, etc.) - What exactly is failing?
- SPF fail
- DKIM fail
- DMARC fail
- or “passes individually but DMARC fails”
- Paste the headers from a message that failed authentication
Specifically, look for:Authentication-Results:Received-SPF:DKIM-Signature:From:
- Paste your DNS records for:
- SPF TXT record
- DKIM public key record
- DMARC TXT record
You can redact domains/IPs if needed, but keep the structure.
Common causes
SPF fails
- You have more than one SPF record for the same domain.
- The sending IP/service is not included in the SPF
include:orip4/ip6. - SPF hits the 10 DNS lookup limit.
- You’re sending from a service that uses a different envelope-from / return-path domain.
- The mail is sent through a relay not authorized in SPF.
DKIM fails
- Wrong selector in DNS.
- DKIM key copied incorrectly or missing characters.
- Mail is being altered after signing:
- disclaimers added
- subject rewritten
- line wrapping changed
- footer inserted
- The signing server is not the one you expect.
DMARC fails
DMARC passes only if SPF or DKIM passes AND aligns with the visible From domain.
So DMARC can fail even if:
- SPF passes but uses a different domain than
From: - DKIM passes but is signed with a different domain than
From:
Quick checks you can do now
- Make sure there is only one SPF record per domain.
- Ensure your DMARC policy starts with
p=nonewhile testing. - Confirm DKIM is enabled on the actual sending service.
- Check whether the
From:domain matches the SPF/DKIM authenticated domain. - Verify no mail gateway is modifying outgoing messages.
If you want, paste this and I’ll interpret it
Headers:
Authentication-Results: ...
Received-SPF: ...
DKIM-Signature: ...
From: ...
DNS records:
example.com TXT "v=spf1 ..."
selector._domainkey.example.com TXT "v=DKIM1; k=rsa; p=..."
_dmarc.example.com TXT "v=DMARC1; p=none; ..."
If you share the header output, I can usually tell you exactly what’s wrong.