Dealing with DMARC for Mail intermediaries


I’ve been getting some mail and calls from folks looking for help on resolving the issue of DMARC bouncing. Some of these calls are from ESPs, but others are from SAAS providers who have users that have signed up with addresses and are now dealing with mail from those users bouncing, even when mail is going back too those users.
None of the solutions are really great, but here are a couple options.
1) Prohibit users users from sending with header-from addresses. This will be challenging for some companies for all sorts of reasons. I have seen a number of people suggest switching to or addresses. This only works as long as Gmail and Hotmail/Outlook don’t start publishing p=reject policies. It’s unclear if they’re even considering this at all, but it may happen.
2) Rewrite the header-from address from to something you control. One thing I’ve been suggesting to customers is set up a specific domain for rewriting, like This domain would need to forward mail back to the users, which does add another layer of complexity as these addresses will become spam magnets. Thus the forwarding IP should be on a distinct and separate IP, to prevent interference with other systems. Note, too, that any users sending to these reply addresses from a domain protected by DMARC p=reject will bounce.
If you have questions or want to ask specifically about what to do in your setup, I’ve blocked out some time in my schedule next week for companies. If you want more information about this please contact me to for available times, information requirements and pricing.

About the author


This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • MailMan appear to be adding a (multipart MIME ?) wrapping of the original message, but I didn’t see any details about how that will work.
    Any thoughts ?

By laura

Recent Posts


Follow Us