Escalate DMARC policy
-
Inventory every sender: ZeptoMail (human), Resend (app), Customer.io / marketing, Workspace if any, ticketing, etc.
-
Ensure SPF
include:chains and DKIM selectors exist for each in Cloudflare (viainfrawhere possible). -
Run
p=nonewithrua=reporting for 1–2 weeks; clear unexplained failures. -
Set
p=quarantine; monitor for another period. -
Set
p=reject. -
Keep reviewing aggregate reports — spoof attempts still appear with disposition
reject.
Example TXT shape (values are illustrative):
v=DMARC1; p=reject; rua=mailto:[email protected];
See DMARC policy path.