DMARC Analyzer

DKIM result: fail

fail covers several distinct underlying problems the aggregate report doesn't always distinguish: the message body/headers changed after signing (some mailing lists and forwarders rewrite content, breaking the signature), the selector's DNS key record was deleted or rotated, or the signature was simply malformed. A known-good sender with a sudden spike in DKIM fail is worth checking for a recent key rotation or a mail-flow change.

References