Deliverability · Practical guide

DMARC subdomain policy: inventory inherited and explicit behavior

Map the root domain and its sending subdomains before changing DMARC policy that can affect more than one mail stream.

Reviewed · Examples are illustrative

Who this helps: Operators diagnosing authentication, receiving-policy and delivery failures.

Define the decision

Subdomains often separate billing, product notifications and outreach ownership. A root-policy change can reach streams managed by other teams. The current DMARC specification also distinguishes existing and nonexistent subdomains.

Work through the procedure

  1. List actual From domains and the DNS records relevant to their policy discovery.
  2. Identify which streams publish their own policy and which depend on organizational-domain policy.
  3. Review p, sp and any applicable np behavior with the domain owner.
  4. Test representative messages and record the receiver’s applied policy before enforcement changes.

Worked example

The following is a synthetic example for this procedure, not a customer result or performance benchmark.

Inventory: example.com, billing.example.com, outreach.example.com
Billing owner: finance platform administrator
Outreach owner: sales operations
Change gate: both streams reviewed before tightening the organizational-domain policy

Read the result

The output should be a domain-to-owner map with expected and observed policy. A single DNS screenshot does not establish what a receiver applied to every subdomain.

Check before moving on

  1. Separate existing subdomains from nonexistent-domain cases.
  2. Check actual From domains rather than just website hostnames.

Limits and next action

Use RFC 9989 for current semantics and account for receiver transition differences. Avoid treating an sp tag placed anywhere in the hierarchy as a universal override.

Source: RFC 9989: subdomain policy and discovery

Source references

Worked examples are illustrative. Editorial procedures are suggested methods, not measured performance claims or promises of additional product features.

Related guides

Explore the Zintara workflow