DMARC compliance is a big part of a good email delivery reputation, but simply adopting and configuring DMARC is not the end of the journey, you need to keep monitoring DMARC compliance. There are several reasons to keep a watchful eye on DMARC compliance rates and the underlying SPF and DKIM compliance rates. Let’s take a look at a few recent examples.
The Customer
We recently had a customer with a sudden drop in SPF compliance affecting their email reputation. It could only be detected through regular monitoring of SPF Authentication through aggregated DMARC reports from Inbox Providers. At the same time, there appeared to be an increase in email volume, however, seasonal variations in outbound email volume may make that difficult to track.
Troubleshooting
There could be several reasons for a change in SPF compliance: an alteration to the SPF record or one of its underlying included SPF records from 3rd party providers, a phishing attempt using the customer’s domain or a new email source. To troubleshoot an issue like this, you need to know who the actual Sender is.
DMARC reports contain details of sending IP addresses, but not the company name. MxToolbox Delivery Center aggregates DMARC reports from the Inbox Providers and then correlates IP addresses in these reports with our databases of known 3rd party senders to determine if they are risky or legitimate. If legitimate, then the sender could be missing from the SPF record or there could be an updated range of IP addresses the customer or 3rd party sender failed to include in the SPF record.
In this case, MxToolbox determined that the sender was MailChimp, a legitimate provider of marketing email. An internal investigation by our client found that a department had started using MailChimp without informing IT. Without MailChimp’s sending IP addresses in the SPF record, much of that email had been rejected. The other department had been puzzled by low campaign open rates, but, had not realized that it was due to the sender being absent from the SPF record. Continued SPF Authentication issues could escalate the reputation issue potentially causing blacklisting of those IPs or wholesale rejection of email from that sender.
Other Issues
Another reason SPF compliance could suddenly drop is phishing attempts using your domain. A bad actor can use your domain for phishing attempts, suddenly increasing the volume of email appearing to come from your domain. Phishing is a huge security threat for both your domain and your internal staff. Again, investigations require aggregated DMARC reports to understand and uncover the issue. The only way to prevent phishing is to adopt DMARC reject policies.
How does MxToolbox Help?
MxToolbox Delivery Center provides everything you need to manage and maintain DMARC compliance rates, including:
- Setup SPF, DKIM and DMARC for your Domain
- Carefully migrate to a DMARC Reject policy
- Setup your BIMI record to get your logo in the Inbox
- Verify compatibility of your SVG image
- Monitor your certificates for expiration
- Manage the on-going changes to the DMARC, SPF, DKIM and BIMI standards
If this sounds complicated, MxToolbox also offers Managed Services team that can help you setup DMARC, DKIM, SPF, BIMI and get your domain aligned with Google, Yahoo! and Outlook.com bulk sender policies.





