System administrators upgrading DMARC from to and accidentally causing third-party transactional mailers (billing, notifications) to get rejected by Gmail.
Has anyone else run into this, and what is the standard engineering fix?
System administrators upgrading DMARC from to and accidentally causing third-party transactional mailers (billing, notifications) to get rejected by Gmail.
Has anyone else run into this, and what is the standard engineering fix?
Setting a DMARC policy of instructs receiving mail servers (Google, Microsoft, Apple) to outright delete or block any email claiming to come from your domain that fails both SPF and DKIM alignment.
If you change to before verifying all third-party sending services (billing software, CRM, support desk, ESPs), legitimate operational emails will be silently blocked.
Set your DMARC record to collect RUA aggregate reports for 2–4 weeks:
Ensure all legitimate services (e.g. AutoSend, Stripe, Zendesk) have custom DKIM keys signed on your exact domain (Strict Alignment). Once alignment is confirmed across 100% of volume, update DMARC to quarantine:
After 2 weeks with zero legitimate quarantine flags, enforce full rejection: