# Delivery Status Notification (Failure)

**URL:** <https://forum.dmarcian.com/t/delivery-status-notification-failure/1304>\
**Category:** Technical Help\
**Created:** [August 6, 2020, 4:48pm UTC](https://forum.dmarcian.com/t/delivery-status-notification-failure/1304 "2020-08-06T16:48:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jminshull](https://avatars.discourse-cdn.com/v4/letter/j/c5a1d2/32.png) [@jminshull](https://forum.dmarcian.com/u/jminshull)\
**Post date:** [August 6, 2020, 4:48pm UTC](https://forum.dmarcian.com/t/delivery-status-notification-failure/1304/1 "2020-08-06T16:48:20Z")

</div>

We send email (AR Statements) to customers through our CDK Global dealer management software. Recently, about half of the emails are failing, while the other half are delivered/received successfully. According to the email header SPF passes but DMARC fails. This contradicts dmarcian’s domain checkers which indicate that DMARC is valid but that we don’t have an SPF record… this is confusing to me because we do have an SPF record and as such I am having difficulty determining where the problem is. Any suggestions would be most welcome. Thank you.

Subject: Delivery Status Notification (Failure)  
SPF: PASS with IP 207.186.148.25 Learn more  
DMARC: ‘FAIL’ Learn more

ARC-Authentication-Results: i=1; mx.google.cxm;  
spf=pass ([google.com](http://google.com): best guess record for domain of  
postmaster@laspsmtp.cdk.cxm designates 207.186.148.25 as permitted  
sender) smtp.helo=laspsmtp.cdk.cxm;  
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=cdk.cxm  
(domains edited by me so they aren’t links…)

## DMARC

Your domain has a valid DMARC record and your DMARC policy will prevent abuse of your domain by phishers and spammers.

## SPF

Your domain does not have a SPF record.

## DKIM

Your DKIM record is valid.

---

<div class="post-metadata">

**Author:** ![beekeeper](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/beekeeper/32/39_2.png) [@beekeeper](https://forum.dmarcian.com/u/beekeeper)\
**Post date:** [August 7, 2020, 5:59pm UTC](https://forum.dmarcian.com/t/delivery-status-notification-failure/1304/2 "2020-08-07T17:59:48Z")

</div>

Hi Jack,

Is it your bounce emails that are failing Dmarc and therefore that are affecting your dmarc stats?

I can see that you have an SPF record for [cdk.com](http://cdk.com) but not for the HELO string of [laspsmtp.cdk.com](http://laspsmtp.cdk.com)  
You could try adding an SPF record for that.

Just a thought.

---

<div class="post-metadata">

**Author:** ![Asher](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/asher/32/104_2.png) [@Asher](https://forum.dmarcian.com/u/Asher)\
**Post date:** [August 14, 2020, 1:18pm UTC](https://forum.dmarcian.com/t/delivery-status-notification-failure/1304/3 "2020-08-14T13:18:46Z")

</div>

Hi Jack,

To add to @beekeeper 's comment, based on the headers Google did a “best guess” check. They do that when the domain as per RFC it is meant to check has no SPF record. While the header from is mentioned to be cdk.cxm, SPF checks are not done against the domain of that email address, also known as the RFC5322 From Header. An SPF check is done by the receiver by looking up an SPF record in the domain extracted from the return-path address, also known as the RFC5321 Mail From ([https://tools.ietf.org/html/rfc7208#section-1.1.3](https://tools.ietf.org/html/rfc7208#section-1.1.3)).

Either the return-path here used is postmaster@laspsmtp.cdk.cxm, or it was null and laspsmtp.cdk.cxm was given as the EHLO identity. Either way, a subdomain does not inherit the SPF record from its parent. This means laspsmtp.cdk.cxm will need its own SPF record if the current way of sending these emails will be maintained.

I hope this helps.

Ash
