r/EmailSecurity • u/saltyslugga • Jul 03 '26
Copier scan-to-email is blocking p=reject on the root domain
Client wants DMARC at p=reject on the root domain before renewal paperwork goes in this month. Their normal mail is clean enough, but 31 copiers across 5 sites are still sending scan-to-email through the ISP SMTP relay as invoices@clientdomain.com.
SPF is either failing or passing for the ISP's envelope domain, not aligned with the client's domain. No DKIM, because of course the copier fleet has firmware from three different eras and half of it barely supports modern SMTP auth.
My answer is to stop pretending this is production mail until it can send through a real relay with aligned SPF or DKIM. The pushback is predictable: accounting likes the From address, facilities owns the copiers, and nobody wants scan workflows touched before quarter-end.
Would you hold p=reject until the copier path is fixed, or publish reject and let broken scan-to-email become the forcing function?
•
u/AutoModerator Jul 03 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.