Inventory every legitimate sender
Before tightening policy, identify Google Workspace, website forms, CRM systems, marketing platforms, support tools and any other service authorized to send as the domain.
SPF, DKIM and DMARC are separate controls that work together. SPF identifies authorized senders, DKIM adds a cryptographic signature and DMARC evaluates domain alignment and defines how failures should be handled and reported.
Your domain has incomplete, conflicting or unverified email authentication and you need it configured without disrupting legitimate senders.
A broken SPF record can cause legitimate sources to fail authentication.
Missing DKIM removes an important cryptographic identity signal.
An aggressive DMARC policy deployed too early can reject legitimate business mail.
Before tightening policy, identify Google Workspace, website forms, CRM systems, marketing platforms, support tools and any other service authorized to send as the domain.
Authentication is useful when the visible From domain aligns with the identities validated by SPF or DKIM. That relationship matters more than the presence of three DNS records.
Monitoring can reveal legitimate services that are not aligned. Enforcement should follow evidence rather than a copied p=reject record.
You do not need to diagnose it before contacting DSDillon. Tell us what is happening, what changed and what outcome the business needs.