Escalate DMARC policy

  1. Inventory every sender: ZeptoMail (human), Resend (app), Customer.io / marketing, Workspace if any, ticketing, etc.

  2. Ensure SPF include: chains and DKIM selectors exist for each in Cloudflare (via infra where possible).

  3. Run p=none with rua= reporting for 1–2 weeks; clear unexplained failures.

  4. Set p=quarantine; monitor for another period.

  5. Set p=reject.

  6. Keep reviewing aggregate reports — spoof attempts still appear with disposition reject.

Example TXT shape (values are illustrative):

v=DMARC1; p=reject; rua=mailto:[email protected];