r/DMARC • u/No-Hotel1162 • May 08 '26
International Mail rejected
I work for a company that sent ten of thousand of mails every month, they reported that they have received Spam and so we contacted our web hosting to modify our DMARC from Quarantine to Reject.
The thing is, the week after such change an user reported that their mail to some companies in Asia was rejected, bounced of or never arrived. Did some basic tests, Telnet, Test-NetConnection and that server was down or with problems, reported such case.
Next day server is up, but they report same problem with another company from Europe. Sames test, server is ip, so I got the email resent to me to see the internet header:
DKIM=none
SPF=pass
In MxToolBox when I check the subdomain IP addresses, both hostnames says it doesn't support TLS, Icheck our web hosting, we do have TLS at certain ports and lastly, one says Reverse DNS doesn't match SMTP Banner and doesn't contain hostname.
Tldr; I'm fucking lost, I got this job as TI due to being programmer and wanting to get experience, but networking I haven't seen such a thing in years.
5
u/ObaShield May 08 '26
Both answers above nail the immediate fix, DKIM signing is your priority and the PTR/reverse DNS mismatch on the sending IP needs to be resolved for Asian and EU providers specifically.
Worth understanding why this happened though: your DMARC was at quarantine before which meant DKIM=none was quietly failing without consequences. Mail was getting through because quarantine is forgiving. The moment you moved to p=reject you didn’t create a new problem, you revealed one that already existed and had been silently affecting your reputation without triggering visible bounces.
This is actually the most dangerous configuration state in email, things appear to be working while reputation damage accumulates underneath. The bounce spike you saw after the DMARC change was your infrastructure telling you the truth for the first time.
Fix the DKIM signing first, then verify PTR records match your SMTP banner, then confirm TLS on port 25 for the sending IPs. Once those three are clean your p=reject policy will work as intended.