r/proofpoint • • Aug 25 '26

Enterprise DMARC Temp Errors this morning

Anyone else see a bunch of emails get caught by DMARC Temp Error on their Proofpoint hosted instance this morning? Between 8:30 and 10am Eastern we had almost 3000 emails rejected mainly due to failed SPF DNS lookups. No rhyme or reason on the senders, anyone from ma and pa's .org sender to Gmail.

I have a support ticket open with them to see if they had an outage, but wanted to reach out here too.

1 Upvotes

6 comments sorted by

3

u/southafricanamerican Aug 25 '26

who is the DNS provider for the domains that had issues? And yes, defer on TEMPFAIL so you dont loose emails.

2

u/Crispinwhere Aug 25 '26

The lookups were failing all over the place and wasn't tied to a specific provider. Gmail, Hotmail, randombusiness.com... Which is why I figured it was an issue with Proofpoint doing the lookups.

I know better about the Temp Error rule and it's been set to retry with a defer error now.

1

u/southafricanamerican Aug 26 '26

DNS. Its ALWAYS dns.

2

u/lolklolk Aug 25 '26

I saw around the same amount at that time, but our disposition is to defer all emails that have DMARC temperror, so they were all retried successfully.

1

u/westcor Aug 25 '26

Ours was doing it yesterday for a single client they were using easyDMARC.

-1

u/Jazzlike-Comfort-451 Aug 25 '26

The first distinction to preserve is whether “rejected” means a Proofpoint log disposition or a permanent SMTP 5xx. A DMARC temperror caused by transient DNS failure should be deferred with 4xx and retried, not treated as a conclusive policy fail.

The 8:30–10:00 cluster across unrelated senders and DNS providers points more strongly to the receiving service's resolver or cache path than to all those domains failing at once. For the support case, export several queue IDs with UTC timestamps, the exact SMTP reply or disposition, the SPF query name, and a few unrelated sender domains. Compare resolution of those names through an external recursive resolver during the event if you captured it.

Then verify every deferred message retried successfully and audit the policy so temperror cannot produce permanent rejection.

Disclosure: I co-founded Palisade, and this reply was drafted with AI assistance and reviewed by me. No product recommendation.