Your DKIM signatures are being broken on the way
MINORWhat it means
N sources show a signature from your own domain that failed verification on relayed mail. Something between you and the recipient is editing messages, a mailing list footer, a subject-line tag, or a gateway rewriting the body, and that edit invalidates the signature.
How to fix it
Sign with relaxed/relaxed canonicalisation so light reformatting survives, and keep signed header lists short. Mailing lists that rewrite the From address will always break DKIM, and ARC is the only real answer there.
Check your own domain
This page describes the condition. To find out whether your domain has it, run the RUA test or the full checkup, which examines every record at once.
Understand it properly
This page covers one condition. For the whole picture, The DMARC guide, including how reporting works, or start at the Health Library.
Where this comes from
We judge this against RFC 9989 section 4.4.1. Every finding on this site cites the specification behind it so you can check the work rather than take our word for it.
Other RUA conditions
RUA_DKIM_BROKEN_IN_TRANSIT
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.