Cross-domain report-destination authorization check
If a domain's rua= address lives on a different domain (e.g. example.com's reports go to a mailbox at reports.example-corp.net), RFC 7489 requires the destination domain to publish an authorization record — example.com._report._dmarc.example-corp.net — proving it consents to receive reports about example.com. Without it, some receivers refuse to send reports there at all.
This check derives the expected destination dynamically from live DNS (parsing the domain's own published rua=) and verifies the record exists. The domain page's "Cross-domain report authorization" card separately predicts the exact record text you'd need — from app.mail_from's domain — so you can copy-paste it into DNS before the record (or even the domain's own rua=) exists yet.
The two can legitimately disagree: this check can show pass while the card still shows a record to add, if the domain's rua= currently points somewhere else entirely (a different DMARC vendor, say) that already authorized itself correctly — that's not a problem with the domain's current setup, it just means this tool specifically isn't receiving that domain's reports yet.
- RFC 7489 §7.1