Hello,
We're evaluating your product prior to purchasing a license. For inbound checks, I see the following issue; the message was sent with different
13:02:29.271 parse email content with 28052 bytes
13:02:29.271 lookup DKIM-Signature header
13:02:29.271 check dkim header
13:02:29.271 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sendgrid.net;
h=subject:from:mime-version:to:content-type:content-transfer-encoding;
s=smtpapi; bh=OP1O3/Zj/wASuvMkjSjlrLKLbrkMP5kJ+kKbipGUTy4=;
b=fqk8Eb2iI3hMXidhyda6AFTm+CUUdVkBn2O5ybOsagqMWx7XHTZsFIJZRcV4PPLwqznU
FXkWtQ9q0OE1qWak85VJc/yfrIc+j82xtK33dJM9BfIwYB3fGoVDJdEEKLDgvmK7CWYl/z
HnWYyVDVmvZXeexMDtYiqTyi+dyzuYk94=
13:02:29.271 check signer
13:02:29.271 check signer d=sendgrid.net; i=
13:02:29.271 sender or from domain is reply.fundrbird.com
13:02:29.271 warnning: sender domain is not equal to signed domain, it will be failed with dmarc validation!
And further:
13:02:29.286 evaluate alignment by v=DMARC1; p=none; pct=100; rua=mailto:re+vmgkputfgtv@dmarc.postmarkapp.com; sp=none; aspf=r;
13:02:29.286 SPF Alignment Result: fail
13:02:29.286 DKIM Alignment Result: fail
13:02:29.286 DMARC Result: fail
All failures and as a result, the message was rejected. But when I lookup the sender's DMARC policy:
$ host -t txt _dmarc.fundrbird.com
_dmarc.fundrbird.com descriptive text "v=DMARC1; p=none; pct=100; rua=mailto:re+vmgkputfgtv@dmarc.postmarkapp.com; sp=none; aspf=r;"
The policy is none, the DMARC should not be enforced. The other mentioned domain:
$ host -t txt _dmarc.sendgrid.net
_dmarc.sendgrid.net descriptive text "v=DMARC1; p=reject; sp=none; rua=mailto:dmarc_agg@dmarc.250ok.net; ruf=mailto:dmarc_fr@dmarc.250ok.net; fo=1; pct=100; rf=afrf"
That policy is to reject.
Question: is this behaviour correct, or is the check too strong? What would you suggest the way solve this issue? I already asked the original sender to analyse their alignment because my first conclusion is that the signature is incorrect, but the message "warnning: sender domain is not equal to signed domain, it will be failed with dmarc validation!" makes me rethink the situation.
Thanks alot for you help!
Please find original headers here:
https://mxtoolbox.com/Pu...d-4813-a54d-002455921150