Northstar Commerce · example.com
Restore authenticated sending across three services.
Illustrative evidence: public DNS snapshot plus one sanitized received-message header per senderThe domain publishes authentication records, but the supplied evidence does not prove aligned SPF or DKIM for every legitimate sender.
Do not tighten DMARC policy yet. First establish one valid SPF record, enable provider-issued DKIM for each active service, and verify aligned passes from real messages. The customer’s administrator applies every change; MX Audit verifies the result.
Primary mailbox platform
Microsoft 365 · user mail
More than one SPF TXT record is indicated. The final record must be a single, provider-verified policy.
No aligned DKIM pass appears in the supplied sanitized header.
Keep the current monitoring policy until every legitimate sender is aligned.
Provider-issued selector targets plus a new received-message header after activation.
Merge the root SPF policy into one TXT record containing <provider-issued SPF mechanism>. Enable DKIM in the tenant, then publish the two exact CNAME records shown by that tenant as <selector 1 host → provider target> and <selector 2 host → provider target>. Never copy these placeholders into DNS.
Transactional platform
Order and account email
DKIM passes for the vendor domain, but the supplied header does not prove alignment with example.com. The bounce or return-path domain also needs confirmation.
In the authenticated-domain screen, collect the provider-issued DKIM and custom return-path records. Publish only those verified values, send a fresh test, and confirm that either DKIM or SPF aligns with the visible From domain.
Marketing platform
Permission-based campaigns
The service is listed as legitimate, but there is no sanitized header or provider verification screen to establish the correct selectors and alignment path.
Supply the platform’s authenticated-domain screen and one sanitized header from a recent campaign. MX Audit then returns the exact host, record type, target, and verification test for the real account.
DNS is coherent
Exactly one SPF policy at the root; provider-issued DKIM selectors resolve; one syntactically valid DMARC record remains published.
Real messages align
A new sanitized Authentication-Results header proves an aligned SPF or DKIM pass for each included sender.
One correction is included
If an instructed record was applied incorrectly, the sprint includes one bounded correction round and repeat verification.