Skip to content
Inspect My DNS

Mail authentication

DMARC report authorisation

mailauth.dmarc-report-auth

A receiver sends DMARC reports to another domain only if that domain has published that it accepts them; otherwise the reports are discarded without any error reaching you.

What this check measures

A DMARC record names where reports go: rua= for the daily aggregates, ruf= for per-message failure reports. Both are mailto: addresses, and very often the address belongs to someone else — a reporting service, a parent company, an agency. That is allowed, but not unconditionally, because otherwise anyone could publish a DMARC record that points a stranger's mailbox at a flood of reports.

So RFC 7489 §7.1 makes the destination opt in. Before sending reports about example.com to an address at vendor.example, a receiver looks up example.com._report._dmarc.vendor.example and expects a TXT record beginning v=DMARC1. A wildcard — *._report._dmarc.vendor.example — satisfies it for every domain at once, and is how most reporting services publish it.

If the record is missing, the receiver drops the reports. Nothing bounces and nothing is logged anywhere the domain owner can see, so the domain looks as though it is collecting DMARC reports while receiving none — which hurts most during a move towards p=reject, the stage where the reports are what tells you which legitimate senders would break.

Mail delivery is unaffected either way; this is about the reports only. A destination counts as external here when it is neither the domain itself, a subdomain of it, nor a parent of it. The RFC's exact test compares organisational domains, which needs the Public Suffix List, so two registrations owned by the same organisation are treated as external and asked about.

How to fix it

If the destination is a DMARC reporting service, check that the domain has been added to your account there. Services publish the authorisation record — usually as a wildcard — and a domain missing from the account is the common cause.

If the destination is a domain you control, publish v=DMARC1 as a TXT record at <your-domain>._report._dmarc.<destination>. To accept reports for many domains at once, publish it at *._report._dmarc.<destination> instead.

If the address is a leftover from a previous provider, remove it from rua=/ruf= rather than authorising it — the reports are going to someone who is no longer reading them.

References

Run this check on a domain

DMARC report authorisation is one of 62 checks in every report, alongside delegation, mail authentication, TLS and registration.