Skip to content
Clinic open · free diagnosis, no appointment needed2,000+ domains monitored

Unauthenticated mail is getting past your policy

URGENT

RUA · Urgent · costs 25 points · RFC 9989 section 4.5

What it means

You publish p=none, but N failing messages from N unauthorised sources were still delivered normally. Receivers apply your policy at their own discretion, and a partial rollout or a receiver-side exception let these through.

How to fix it

Check the pct tag on your record, anything below 100 tells receivers to apply the policy to a sample only. Then look at the override reasons in the table, which name exactly why each receiver stood down.

Check your own domain

This page describes the condition. To find out whether your domain has it, run the RUA test or the full checkup, which examines every record at once.

Understand it properly

This page covers one condition. For the whole picture, The DMARC guide, including how reporting works, or start at the Health Library.

Where this comes from

We judge this against RFC 9989 section 4.5. Every finding on this site cites the specification behind it so you can check the work rather than take our word for it.

Other RUA conditions

RUA_UNAUTHENTICATED_LEAKING

Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.