← Back to Blog

Lappu AI Journal

Case Studies: Real Email Misconfigurations We Fixed

Real-world email security issues, a DKIM misalignment in Microsoft 365 and a broken DMARC record, and how they impacted DMARC compliance. This highlights the importance of correctly configuring authentication records to ensure deliverability and visibility into potential spoofing.

Lappu AI Staff • September 22, 2025

Case 1: DKIM Misalignment in Microsoft 365 (DMARC Failures Despite Signing)

For One of our clients using Microsoft 365 our platform discvered DMARC failures in their reports, despite having SPF configured and DKIM seemingly enabled. DKIM Discovery:

  • DMARC reports showed that DKIM passed - but not for the client's business domain (yourdomain.com).
  • Instead, DKIM passed for the default Microsoft 365 organization (NETORGXXXXXXX.onmicrosoft.com).
  • Since DKIM alignment failed (the domains didn't match), these messages failed DMARC if SPF didn't pass. Occasional SPF Failure Some recipient mail servers were using outdated or incorrect IP lookup behavior, causing SPF to intermittently fail, even though the client's SPF record was correct. Resolution:
  1. We retrieved Microsoft's recommended CNAME records for enabling DKIM:
selector1._domainkey.yourdomain.com → selector1-yourdomain-com._domainkey.<initial>.onmicrosoft.com
selector2._domainkey.yourdomain.com → selector2-yourdomain-com._domainkey.<initial>.onmicrosoft.com
  1. Added these CNAMEs to the client's DNS records
  2. Enabled DKIM signing for yourdomain.com in Microsoft 365 Admin Center After these steps, DKIM began passing with domain alignment, allowing DMARC to pass even when SPF occasionally failed. This greatly improved overall deliverability and ensured the client's domain couldn't be spoofed easily.

Case 2: Invalid DMARC Record Due to Missing Semicolon

In another case, a business was puzzled as to why no DMARC reports were being generated — even after they had published a p=none DMARC policy. What we found: Their DMARC record looked like this: v=DMARC1 p=none; rua=mailto:dmarc@domain.com Notice the missing semicolon between v=DMARC1 and p=none? This small syntax error caused many receiving mail servers to ignore the DMARC record entirely. As a result:

  • No enforcement took place
  • No aggregate reports were sent
  • The organization had partial visibility into how its domain was being used Resolution: We corrected the record as follows: v=DMARC1; p=none; rua=mailto:dmarc@domain.com Within 24 hours, DMARC aggregate reports started appearing from primary email providers, giving the organization real visibility into its email traffic.

Key Takeaways for Microsoft 365 users

  • DKIM must be configured for your business domain - Microsoft's org name based default domain won't align.
  • SPF failures can happen outside your control, so DKIM is your safety net.
  • Check for syntax issues in DNS records - even one missing semicolon can break everything.
  • Use tools like Lappu AI's SPF and DMARC validators to automatically test and verify all records.
  • Always review DMARC reports using automated tools - they are your radar system against spoofing and misdelivery.