• The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Resolved DMARC function failure

Bobb

New Pleskian
I am running Plesk Obsidian 18.0.34 Update #2 on Centos 7.9. It has two domains installed.
I noticed that I had a problem with my mailserver when a couple of users complained about not being able to send mails to other mailboxes within the same domain and to mailboxes in the other domain on the same server. Emails are being received from external domain and sending out emails to external domains also works.

The mail server is setup with the DMARC, DKIM and SPF protection options and that has been working fine for a cpuple of years.
When checking the MAILLOG I noticed a couple of lines which indicated that DMARC process was dropping email originated within one domain and send to the same domain. If I switch off the DMARC setting for the mailserver mails are send successfully within the domain and to the second domain on the same server.

Apr 2 08:44:51 centos7 dmarc[4734]: Starting the dmarc filter...
Apr 2 08:44:51 centos7 dmarc[4734]: Store DKIM result for 'domain1.net' into DMARC library.
Apr 2 08:44:51 centos7 dmarc[4734]: Wrong the essential DMARC policy parameters for 'domain1.net': 'Found DMARC record containd a bad token value'
Apr 2 08:44:51 centos7 dmarc[4734]: DMARC: smtpdomain=domain1.net maildomain=domain1.net mailfrom=[email protected] stamp=1617345891 ip=127.0.0.1 adkim=unspecified aspf=unspecified p=UNSPECIFIED sp=UNSPECIFIED pct=100 align_dkim=fail align_spf=fail spfres=pass dkimres=pass dmarccheck=DMARC_POLICY_REJECT dmarcstatus=STOP
Apr 2 08:44:51 centos7 dmarc[4734]: DMARC: REJECT message for [email protected]

The DMARC DNS record is standard and hasn't changed for months; v=DMARC1; p=quarantaine; sp=quarantaine; rua=mailto:[email protected]; ruf=mailto:[email protected]

I have tried recreating the the DNS record and changing the policy to the default v=DMARC1; p=none. But that didn't change anything.

any suggestion where to look firther?
 
Additional.
If I check the authentication result when sendin a message to Google I get the results:
dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=domain1.net
 
Yes, did and it showed no errors. It validated. But as I wrote the DMARC policy has been working for more then a year and I haven't changed the policy setting (defined in the DNS record) for a long time.
 
Yes, did and it showed no errors. It validated. But as I wrote the DMARC policy has been working for more then a year and I haven't changed the policy setting (defined in the DNS record) for a long time.
Correction, there was a typo mentioned but after correction it that didn't change the outcome.
 
Digging further I came to the conclusion that what is shown in the Plesk panel as DNS records is not the same what I recover via the commandline.
The Plesk screen shows: v=DMARC1; p=quarantine; sp=quarantine; rua=mailto:[email protected]; ruf=mailto:[email protected]
The 'dig TXT _dmarc.domain1.net' command shows:
;; ANSWER SECTION:
_dmarc.domain1.net. 69731 IN TXT "v=DMARC1; p=quarantaine; sp=quarantaine; rua=mailto:[email protected]; ruf=mailto:[email protected]"

This has the type 'quarantaine' in it. But the update of the record doesn't seem to trickle down.
 
Issue resolved.
The issue was with a server from the supplier which gave mixed responses on the _dmarc request; one respose with "v=DMARC1; p=quarantaine; ..." and next with "v=DMARC1; p=quarantine;...."
 
As I wrote the DMARC policy has been working for more then a year and I haven't changed the policy setting (defined in the DNS record) for a long time.

You are right, it was working fine until recently. But this is not the kind of issue I would expect from mail delivery. It looks like a problem with my MX records or something like that.

I also tried to set up DMARC on my domain's main domain name as well but didn't receive any email from Google, Outlook or other providers either.
 
Back
Top