To help eliminate spoofing I enabled the setting on smartermail to use the FROM instead of the RETURN PATH field for SPF / DMARC.
Ever since then we have been having problems with DMARC rejecting emails coming in to specific people. I have added the SPF entry for the sending domain to our SPF, and it still is failing DMARC.
Any advice? I have swapped my client's domain and email for privacy reasons.
Anywhere you see Last, First would actually be their name, and
person@companyemail.com would actually be their real email address.
This is from our SMTP logs
[2022.02.11] 11:22:38.361 [147.253.217.248][64957876] Performing PTR host name lookup for 147.253.217.248
[2022.02.11] 11:22:38.376 [147.253.217.248][64957876] PTR host name for 147.253.217.248 resolved as mta-253-217-248.netsuite.com.sparkpostmail.com
[2022.02.11] 11:22:38.376 [147.253.217.248][64957876] rsp: 354 Start mail input; end with <CRLF>.<CRLF>
[2022.02.11] 11:22:38.501 [147.253.217.248][64957876] senderEmail(2): system@sent-via.netsuite.com parsed using: "Last, First (person@companyemail.com)" <system@sent-via.netsuite.com>
[2022.02.11] Reply-To:"Last, First" <person@companyemail.com>11:22:38.501 [147.253.217.248][64957876] rsp: 550 Message rejected due to senders DMARC policy
[2022.02.11] 11:22:38.501 [147.253.217.248][64957876] A trace of the DMARC processing follows.
[2022.02.11] 11:22:38.501 [147.253.217.248][64957876] Beginning DMARC check for msprvs1=19041PBDFoaIN=bounces-183799-1@sent-via.netsuite.com from IP 147.253.217.248...
[2022.02.11] 11:22:38.501 [147.253.217.248][64957876] The from field for the message is ""Last, First (person@companyemail.com)" <system@sent-via.netsuite.com>". Will look for DMARC policy record at _dmarc.companyemail.com
[2022.02.11] 11:22:38.501 [147.253.217.248][64957876] Retrieved the following DMARC policy record for "companyemail.com": v=DMARC1; p=reject
[2022.02.11] 11:22:38.501 [147.253.217.248][64957876] DMARC policy violated due to DKIM domain ("System.Collections.Generic.List`1[System.String]") not belonging to the same parent domain as the from address field domain ("companyemail.com").
[2022.02.11] 11:22:38.501 [147.253.217.248][64957876] DMARC policy violated due to SPF domain ("sent-via.netsuite.com") not belonging to the same parent domain as the from address field domain ("companyemail.com").
[2022.02.11] 11:22:38.517 [147.253.217.248][64957876] Received message size: 43577 bytes
[2022.02.11] 11:22:38.517 [147.253.217.248][64957876] Successfully wrote to the HDR file. (C:\SmarterMail\Spool\SubSpool6\960192956765.hdr)
[2022.02.11] 11:22:38.517 [147.253.217.248][64957876] Data transfer succeeded but message rejected by DMARC
[2022.02.11] 11:22:43.563 [147.253.217.248][64957876] cmd: QUIT
[2022.02.11] 11:22:43.563 [147.253.217.248][64957876] rsp: 221 Service closing transmission channel
[2022.02.11] 11:22:43.563 [147.253.217.248][64957876] disconnected at 2/11/2022 11:22:43 AM