Subdomains not protected
Subdomain traffic is outside effective DMARC coverage.
Problem summary
Subdomain traffic is outside effective DMARC coverage.
Symptoms
- Apex has DMARC but subdomain From addresses are uncovered
- sp= missing or weaker than intended
- Spoofing succeeds on marketing.example.com while example.com is enforced
Possible causes
- No sp= tag and receivers not applying expected inheritance
- Explicit weaker policy on the subdomain
- Subtree domains with their own organizational DMARC needs
How to diagnose
- Map From domains in use (apex vs subdomains)
- Inspect apex DMARC sp= and any subdomain _dmarc records
How to fix
- Set sp= to match intended subdomain policy on the org DMARC record
- Publish explicit _dmarc on subdomains that need different handling
- Authenticate subdomain senders before enforcing on them
How to verify
- Subdomain test From addresses see the expected DMARC policy
- Reports include subdomain traffic as expected
Prevention
- Include subdomain From identities in auth design
- Review sp= whenever apex policy changes
When to escalate
- Production mail is failing for a material share of recipients after remediation attempts