DomainCanary Start free

Bounce and error codes

dmarc=fail (p=REJECT) in Authentication-Results

Last updated 14 Aug 2026

The receiver ran DMARC on your From domain, the check failed, and your policy of p=reject told it to refuse the message. The Authentication-Results header carries the whole diagnosis in one line: which checks passed, for which domain, and why none of them aligned. Read that line field by field before you change anything.

The line

Authentication-Results: mx.google.com; dkim=pass header.i=@vendor.net header.s=s1 header.b=Ab3dEf01; spf=pass (google.com: domain of bounces@vendor.net designates 203.0.113.24 as permitted sender) smtp.mailfrom=bounces@vendor.net; dmarc=fail (p=REJECT sp=REJECT dis=NONE) header.from=example.com

Two passes and a failure. Nothing here is broken at the vendor, and nothing here helps you. Read it field by field.

  • dkim=pass header.i=@vendor.net. The signature verified, for vendor.net. The domain that matters for DMARC is the signing domain d=, reflected here as header.i. It is not your domain, so it does not align.
  • spf=pass ... smtp.mailfrom=bounces@vendor.net. SPF passed for the envelope sender domain, which is the vendor's. Also not your domain, also no alignment.
  • header.from=example.com. This is the identity DMARC protects, and the reader sees it. Neither passing check matched it.
  • p=REJECT. Your published policy, echoed back. sp=REJECT is what applies to subdomains.
  • dis=NONE. The disposition actually applied. This message was delivered despite the policy, which is why you may be seeing failures with no bounces yet. Somewhere else, another receiver is applying dis=reject and you never hear about it except in aggregate reports.

What alignment requires

DMARC passes when at least one of these is true, with the default relaxed matching:

  • SPF passes and the envelope sender domain is your From domain or a subdomain of it. So bounces.example.com aligns with example.com, and bounces.vendor.net never does.
  • DKIM verifies and the signature's d= is your From domain or a subdomain of it.

Set aspf=s or adkim=s and the subdomain latitude disappears; an exact match is then required. The alignment guide works through the cases with real header examples.

Where to find the header

  • Gmail: open the message, three dots, Show original.
  • Outlook on the web: three dots, View, View message source.
  • Microsoft 365: the same line plus compauth=fail reason=000, Microsoft's composite verdict. A compauth failure with everything else passing usually means alignment as well.
  • Anywhere: send a message to a mailbox you control at a provider that writes this header. Gmail is the most readable.

Fix it

  1. Identify the sender from smtp.mailfrom or header.i. That domain names the vendor.
  2. Complete that vendor's domain authentication so it signs with d=example.com. This is the fix that also survives forwarding. The provider pages have the records for the common ones.
  3. Set a custom return-path if the vendor offers one, which gets SPF aligned as well and gives you two passing paths instead of one.
  4. Verify with the DKIM checker that the selector the vendor asked you to publish resolves, then send a test and read the header again. You want dkim=pass header.i=@example.com.

One header tells you about one message. Aggregate reports tell you about every sender at once, which is the only way to know you have found them all before you tighten a policy. Reading a report by hand is the next page to read, and our weekly digest does it for you if you would rather not.

Still seeing dmarc=fail (p=REJECT)?

Check the domain in your From address. SPF, DKIM and DMARC in one pass, no signup.

Free · No signup · The result names what to change

Questions

How can SPF pass and DMARC fail on the same message?

SPF authenticates the envelope sender, DMARC checks the visible From header. When mail goes out with a vendor return-path, SPF passes for the vendor's domain and aligns with nothing in your From address, so DMARC fails.

What does dis=none mean next to p=REJECT?

The receiver read your reject policy but chose not to apply it to this message, usually because it is local mail, a trusted forwarder, or ARC-sealed. Do not read it as passing.

Is header.from the same as the address I typed in the client?

Yes, it is the domain part of the visible From address, the one the recipient sees. smtp.mailfrom is the envelope address used for bounces, which recipients never see and which platforms routinely set to their own domain.