R5 — Unknown source, sustained auth failures above threshold
← All help articles · Recommendation rules
Triggers when: an unknown source IP has a volume of messages failing both SPF and DKIM above the configured threshold, within the standard analysis window.
What to do: investigate the source (rDNS/ASN enrichment on the domain page's source table is the starting point). This is deliberately phrased as "investigate," not "block" — a domain spoofing your name toward a third party's inbox isn't necessarily hitting your own mail server, so blocking based on aggregate-report data alone isn't justified; only act on traffic you've also observed on your own MX.