DMARC Analyzer

R9 — Published policy drifted from approved baseline

← All help articles · Recommendation rules

Triggers when: the normalized current_published_policy (read live from DNS) differs from the approved_baseline_policy you deliberately set — and only once a baseline actually exists, since there's nothing to drift from before that. This is the same condition the daily alerting digest's policy-drift check watches, computed independently so it doesn't depend on this rule engine having run.

What to do: a mismatch means either someone changed the DNS record outside your normal process, or DNS itself was tampered with — treat it as worth investigating promptly, not routine drift. If the change was intentional, re-approve the new policy as the baseline once you've confirmed it.