Your own mail is failing authentication
URGENTWhat it means
N messages (N% of your volume) came from N sources that identify themselves with your domain and still failed DMARC. That is a broken configuration, not an attacker, and the moment you enforce a policy, this is the mail you lose.
How to fix it
For each source below: if it signs with DKIM, the selector or key is wrong, republish the key your platform gives you. If it only uses SPF, add its sending hosts to your SPF record. Fix these before tightening your policy.
Check your own domain
This page describes the condition. To find out whether your domain has it, run the RUA test or the full checkup, which examines every record at once.
Understand it properly
This page covers one condition. For the whole picture, The DMARC guide, including how reporting works, or start at the Health Library.
Where this comes from
We judge this against RFC 9989 section 4.4. Every finding on this site cites the specification behind it so you can check the work rather than take our word for it.
Other RUA conditions
RUA_OWN_MAIL_FAILING
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.