Usually one of four things: a service you use (a CRM, a newsletter tool) isn't in your SPF record; the sender isn't signing with DKIM; the From address doesn't match the domain that SPF or DKIM authenticated (called alignment); or the mail was forwarded, which breaks SPF and is expected.
Sending Sources shows you which sender is failing and why, and the AI "Explain this failure" button on any row gives a plain-English answer.
Mailbox providers send DMARC reports once a day, so expect your first data 24 to 48 hours after publishing the record. If you have a report file already, you can upload it to see data immediately.
p=none is monitoring mode. Email that fails DMARC is still delivered as normal; the only difference is that you receive reports about it. It's the right place to start, and the wrong place to stay.
When every legitimate sender is identified and passing SPF or DKIM, you've watched the reports for two to four weeks (long enough to catch monthly sends), and your alignment is above about 95%. The Enforcement Guide gives you a green or amber verdict, and Smart DMARC can step the policy up automatically.
Get the SPF include from the service's documentation and add it to your SPF record (Smart SPF has one-click buttons for the common ones and keeps you under the lookup limit). Turn on DKIM signing in the service's settings. Then watch the reports for a week or two before you rely on it.
SPF checks whether the server that sent the email is on your domain's list of allowed senders. DKIM checks a digital signature added by the sending system, and that signature survives forwarding where SPF doesn't. Use both; DMARC passes if either one passes and aligns with your domain.
Not currently. The outbound chat and ticketing integrations today are Microsoft Teams and ConnectWise PSA. Alerts also go out by email, which most Slack workspaces can receive through an email-to-channel address.
Pull DMARC report data, domain security scores, vendor risk data and audit logs; generate PDF reports; and stream events into a SIEM. See What you can get from the API and rate limits.
DMARCS runs two independent regional deployments, one serving the EU and one serving the UAE, each with its own hosting, database and mail processing. Your data stays in the region your account is hosted in. The Trust Center's Security page has the detail on encryption, access control and audit logging.
For your logo to show in Gmail, yes: a Verified Mark Certificate (VMC), which requires a registered trademark. Some other mailbox providers show BIMI logos without a certificate. BIMI Inspector hosts the logo and record either way, and the VMC Tracker keeps the certificate process on track.
Add /?manual=true to the DMARCS address to get the normal email and password login. Details in Locked out by SSO.
Didn't find your question?
Search the help center from the home page, or ask us directly.