No DMARC record
Without DMARC, anyone can send mail that claims to be from your domain and receivers have no instructions for it. Start with p=none and a report address so you can see who sends as you. DMARC Dojo publishes the record and a private report inbox for you.
Stuck at p=none
p=none only monitors: spoofed mail is still delivered. Move to p=quarantine, then p=reject, once your reports show every legitimate sender passing. DMARC Dojo reads the reports and tells you when each step is safe.
SPF over 10 DNS lookups
Each include:, a, mx and redirect costs a DNS lookup, and SPF allows 10. Past that, receivers return a permerror and SPF fails for all your mail. Remove services you no longer use or replace includes with ip4/ip6 ranges. DMARC Dojo hosts your SPF and blocks changes that would go over the limit.
Multiple SPF records
A domain may have only one v=spf1 record. Two or more is an SPF error, so receivers treat SPF as failed. Merge every mechanism into a single record; DMARC Dojo does this automatically when it takes over SPF.
An email service isn’t signing DKIM with your domain
Services like SendGrid, Mailchimp or Amazon SES sign with their own domain by default, which doesn’t count for DMARC. Turn on custom-domain DKIM in each service and publish the CNAMEs or keys it gives you. The Sources view in DMARC Dojo shows exactly which services still need it.
sp=none leaves subdomains open
A strict main policy with sp=none still lets attackers spoof any subdomain, such as billing.yourdomain.com. Remove sp= so subdomains inherit your policy, or set it to quarantine or reject. DMARC Dojo flags this in every domain report.