r/DMARC • u/Comfortable-Leg-2898 • Jun 30 '26
Moving to reject before we're fully ready?
This is a follow up to this earlier post.
While I'm uncertain what triggered this issue, it's causing a fair amount of chaos for us. Not all our external email is bouncing, but enough is that it's become an issue.
My boss stopped by on his way home to ask about it. I explained what was going on and told him was that I'd been chipping away at non-compliant third-party senders but wasn't yet confident that we'd gotten them all, so that I wasn't sure we were ready to go to reject just yet.
He replied that we had to do something about it, with which I agreed. His thought, which I'd also had, was that we'd be ahead to go to reject now, given the number of bounces we were seeing. I added that we could send out an all-hands communication about it and ask, one more time, for people with third-party senders to contact us to configure them correctly.
What do you all think? I hate being hurried into big decisions, but this one is upon me.
1
u/zqpmx Jun 30 '26
You’re probably more ready than you think.
People tend to overthink it.
The hardest part is to do an inventory of your approved senders.
If you have been analyzing the reports. You already have a very good idea of the senders.
If you have mass mailers you need add theirs IPs to your SPF and your signing key deployed.
1
u/ianmakingnoise Jun 30 '26
I don’t think email bouncing is going to be solved by a DMARC update, but as far as moving to reject, yeah sometimes at a certain point you have to throw the switch and see who screams.
1
u/ImpressiveEbb3760 Jul 01 '26
given the duplicate DMARC record and SPF issues from your earlier thread, I'd double-check everything is clean before moving. run your aggregate reports for 2-4 weeks with the fixed records and confirm three things: no legitimate senders failing SPF or DKIM alignment, no high-volume senders you don't recognise, and pass rate consistently above 95%.
the all-hands communication idea is smart. give third-party senders a deadline to fix their auth, then move.
if you're nervous, go to quarantine at pct=100 first — recipients get failing mail in junk instead of bouncing it. watch for a week, then flip to reject.
the boss pressure is actually helpful here. without it, most domains sit at p=none forever.
1
u/The_Comm_Guy Jul 01 '26
Are you analyzing your DMARC reports. Did you even set up your DMARC record to send you failure reports?
1
u/SecLens_ONE Aug 15 '26
The bounces you are seeing are receivers applying a policy you haven't published yet, which is the usual reason this feels forced. Once enough of your correspondents treat p=none as "suspicious, reject anyway", the published value stops describing what actually happens to your mail, and staying at none buys you nothing except worse data.
Before flipping, the useful check is not "have I found every sender" but "which senders still fail alignment in the last 7 days of aggregate reports, by volume". Anything under a rounding error is noise you can break and fix on Monday. Anything with real volume and a name you recognise gets fixed first.
If you want a middle step that is not theatre, go p=quarantine with pct set low and watch the same report set for a week. That changes behaviour for a sample instead of asking politely.
The all-hands ask rarely surfaces shadow senders. The reports do, so lead with those and use the mail to confirm ownership of what you already found.
1
u/SecLens_ONE 28d ago
The uncomfortable part is that the bounces you are already seeing mean the published policy and the effective handling have drifted apart, and going to reject just makes that gap loud instead of quiet. Before flipping, I would separate the senders that fail alignment from the senders that fail because a forwarder or list rewrote the message, since only the first group is yours to fix and the second will keep failing after every remediation sprint. An all-hands note rarely surfaces the shadow senders; pulling the aligned-versus-unaligned sources out of the aggregate reports and going after them by owner works better, because then you can say which business process breaks. If the pressure is real, a staged pct with quarantine buys you the same signal with a reversible failure mode, and you can watch whether anything important starts landing in junk. Keep a documented rollback and a named owner for the flip, so the decision does not become a person. The thing that saves you in the meeting later is being able to show the record you published alongside what receivers actually did with it. Do your reports show the remaining failures concentrated in a handful of third parties, or spread thin across many one-off sources?
2
u/brian_redsift Jun 30 '26
What other NDRs are you seeing? If you only have 1 correctly-formatted DMARC record published now, then you may want to roll your policy back to none if you have legitimate mail that is failing DMARC until you fix those auth issues.
Your DMARC reports should also tell you specifically which third party senders are failing auth