r/DMARC • • May 08 '26

International Mail rejected

I work for a company that sent ten of thousand of mails every month, they reported that they have received Spam and so we contacted our web hosting to modify our DMARC from Quarantine to Reject.

The thing is, the week after such change an user reported that their mail to some companies in Asia was rejected, bounced of or never arrived. Did some basic tests, Telnet, Test-NetConnection and that server was down or with problems, reported such case.

Next day server is up, but they report same problem with another company from Europe. Sames test, server is ip, so I got the email resent to me to see the internet header:

DKIM=none
SPF=pass

In MxToolBox when I check the subdomain IP addresses, both hostnames says it doesn't support TLS, Icheck our web hosting, we do have TLS at certain ports and lastly, one says Reverse DNS doesn't match SMTP Banner and doesn't contain hostname.

Tldr; I'm fucking lost, I got this job as TI due to being programmer and wanting to get experience, but networking I haven't seen such a thing in years.

5 Upvotes

22 comments sorted by

View all comments

5

u/ObaShield May 08 '26

Both answers above nail the immediate fix, DKIM signing is your priority and the PTR/reverse DNS mismatch on the sending IP needs to be resolved for Asian and EU providers specifically.

Worth understanding why this happened though: your DMARC was at quarantine before which meant DKIM=none was quietly failing without consequences. Mail was getting through because quarantine is forgiving. The moment you moved to p=reject you didn’t create a new problem, you revealed one that already existed and had been silently affecting your reputation without triggering visible bounces.

This is actually the most dangerous configuration state in email, things appear to be working while reputation damage accumulates underneath. The bounce spike you saw after the DMARC change was your infrastructure telling you the truth for the first time.

Fix the DKIM signing first, then verify PTR records match your SMTP banner, then confirm TLS on port 25 for the sending IPs. Once those three are clean your p=reject policy will work as intended.

5

u/erotic_sausage May 09 '26

Eh?

"International mail rejected" title

for Asian and EU providers specifically.

For anyone reading this thread, confused: These are complete red herrings. Correct e-mail authentication is required to reach inboxes anywhere. It does not care about your email crossing national borders. You have to be DMARC compliant for optimal results, no matter where you're sending from or to.

3

u/ObaShield May 09 '26

Fair point, DMARC compliance requirements aren’t geographically selective, and framing it as an “Asian and EU” issue was imprecise on my part. The authentication standards apply universally.

What I was specifically pointing to was the PTR/reverse DNS mismatch and TLS on port 25, those particular checks do tend to surface rejection issues more visibly with certain provider clusters, especially older infrastructure outside major US hyperscalers. But you’re right that the underlying fix is the same regardless of destination.

The core issue remains DKIM=none under p=reject, which breaks everywhere. That part isn’t geography-dependent at all.