Check authentication
Regularly verify SPF, DKIM, and DMARC alignment and report pipelines.
- Difficulty:
- Beginner
- Prerequisites:
- DMARC reporting addresses, DNS inventory
- Last updated:
- 2026-07-15
- Author:
- empire
Objective
Monitor authentication failures
Collect and review authentication and reporting signals.
Starting state
Domains are authenticated; ongoing change risk exists
Prerequisites
- DMARC reporting addresses
- DNS inventory
Estimated time
30–60 minutes
Difficulty
beginner
Required access
- DNS
- DMARC report consumer
- ESP
Inputs
- Domain list
- Recent change log
Step-by-step instructions
- Spot-check DNSConfirm SPF/DKIM/DMARC records still match the intended design.
- Read reportsReview DMARC aggregate data for unexpected sources or failures.
- Sample headersInspect Authentication-Results on live messages after changes.
Verification
- No unexplained fail spikes in DMARC reports
Common mistakes
- Ignoring reports until enforcement blocks mail
- Investigate unknown sources vs immediately reject?
Rollback / recovery
- Revert recent DNS changes if auth failures spike
Expected outcome
Authentication drift is caught before enforcement incidents.
When to escalate
- Unknown high-volume sources appear in DMARC data
Related Learn Articles
- AuthenticationIdentity signals for email: SPF, DKIM, DMARC, and related controls.
- SPFSender Policy Framework — authorizes hosts that may send for a domain.
- DKIMDomainKeys Identified Mail — cryptographic signatures for message integrity.
- DMARCDomain-based Message Authentication, Reporting, and Conformance.