Fixing a Low Pass Rate
Common Causes of Low Pass Rates
1. Missing SPF Include
A third-party service sends email on your behalf but isn't in your SPF record.
Fix: Add the service's include: mechanism to your SPF record. Check the service's documentation for the correct value.
2. DKIM Not Configured
Your email provider isn't signing outgoing messages with DKIM.
Fix: Enable DKIM in your email provider's admin console. This usually involves adding a CNAME or TXT record to your DNS.
3. Email Forwarding
Forwarded emails break SPF because the forwarding server's IP isn't in your SPF record.
Fix: This is expected behavior. DKIM should still pass for forwarded emails if properly configured. Ensure DKIM is enabled.
4. Multiple SPF Records
Having two TXT records starting with v=spf1 causes SPF to fail entirely.
Fix: Merge all mechanisms into a single SPF record.
5. SPF Lookup Limit Exceeded
SPF has a limit of 10 DNS lookups. Exceeding this causes a permanent error.
Fix: Remove unused mechanisms, use IP addresses (ip4:/ip6:) instead of include: where possible, or use an SPF flattening service.
Debugging Steps
- Check your current records with DMARC Checker and SPF Checker
- Review your DMARC reports to identify which IPs are failing
- Use reverse DNS to identify the sending service
- Add the service to your SPF record or enable DKIM
- Monitor reports for improvement over the next 24-48 hours