Security · Tech Notes

Contact form failures revealed by DMARC

How a client's DMARC reports caught a website contact form quietly failing email authentication, and the one-line SPF fix that resolved it.

January 31, 2024

Most people can grasp how SPF and DKIM records authenticate legitimate email from an organization, especially now that Google and Yahoo enforce new email security requirements. DMARC seems less straightforward at first, but a recent client implementation gave us quick, clear evidence of why it matters.

A quick reminder on SPF and DKIM

  • SPF (Sender Policy Framework) tells the world which outgoing mail servers are allowed to send email on behalf of your domain.
  • DKIM (DomainKeys Identified Mail) proves that an email claiming to come from your outgoing mail server really did.

What DMARC adds

DMARC (Domain-based Message Authentication, Reporting, and Conformance) collects email deliverability reports from mail servers all over the world about mail that is, or appears to be, sent from your domain. The reports list every email that passed or failed SPF or DKIM authentication (did it really come from someone at your organization?) and where the email came from.

The client setup

Our client uses email for basic business correspondence and nothing else: no email marketing, CRM, or online sales. So we set up SPF and DKIM records for Microsoft email services and assumed that would be it. Strictly speaking, a DMARC record wasn't even required by Google and Yahoo, given the low volume of email this client sends each day. We set up DMARC anyway.

Why? Without DMARC, we can't confirm that the SPF and DKIM records are complete. Without the deliverability reports DMARC provides, we have no confirmation that the records we added are the only ones the domain needs.

What the reports revealed

When we reviewed the deliverability reports after two weeks, we saw a dozen messages failing SPF and DKIM, all coming from the same source: a popular web host for WordPress sites. Checking the findings with our client, we discovered together that the contact form on their website was the source. The form was sending email using the client's domain name but from the web host's mail servers.

The remedy was easy: add the web host's mail servers to the domain's SPF record. On our next check, the contact form emails all passed DMARC.

It's easy for any organization to fall into a similar trap. Maybe someone on the sales team is experimenting with a new CRM tool, or server alerts were set up years ago through an SMTP service like Mailgun or Sendgrid. DMARC reports reveal what's missing. Without DMARC, some of these emails that fail authentication will soon start getting rejected.

If your business depends on email for marketing, purchasing, or customer service, ongoing DMARC monitoring and adjustment is essential for protecting your domain's reputation and its deliverability. Read how we helped a retail client deliver 3-5 million emails a month from multiple platforms without getting tagged as spam.

Macktez Domain Management

Macktez has been managing domain health and security for decades, and we can help your organization too. Our Domain Management subscription was designed for email and domain security, and includes all the protocols and ongoing maintenance described above. Beyond setting up and monitoring SPF, DKIM, and DMARC, we make sure your domain is registered at a reputable registrar and that your DNS is hosted with a secure, reliable service. This minimizes the ability of criminals to use your domain for phishing, and gives recipients greater confidence that messages from you are authentic. We monitor DMARC reports and gradually tighten your DMARC policy, making DNS adjustments as needed.

Work With Us

Have a project like this on the horizon?

If something here maps to what your organization is facing, let's talk it through — no pitch deck, just a senior technical perspective on your situation.