R11 — No sp= while subdomain spoofing observed
← All help articles · Recommendation rules
Triggers when: the domain's DMARC record has no sp= tag, and reports show a subdomain (strictly, not the organizational domain itself) appearing in header_from with total authentication failure.
What to do: publish an explicit sp= — usually reject if the domain has no legitimate subdomain-sending traffic — to close off spoofing of subdomains that would otherwise silently inherit whatever the main p= allows.