DMARC Policy Enforcement Update

DMARC Policy Enforcement Update

CUIT is looking to implement changes soon. Columbia University Information Technology (CUIT) will begin enforcing a DMARC policy of p=reject across all levels of Columbia-managed domains. This change represents the final phase of our DMARC implementation. It is intended to significantly reduce email-based spoofing, phishing, and other forms of domain impersonation by preventing unauthorized systems from sending email on behalf of Columbia domains.

Once a domain is set to a DMARC policy of Reject, any email that fails DMARC alignment checks (SPF and/or DKIM) will be rejected by receiving mail systems, rather than quarantined or delivered. As a result, emails sent from third-party platforms, cloud services, or on‑premise systems that are not properly authenticated will not be delivered unless they are correctly configured to meet DMARC requirements.

CUIT recognizes that this enforcement may impact existing email workflows that rely on third-party senders or legacy systems. All affected services must be reviewed and remediated prior to enforcement by ensuring proper SPF, DKIM, and DMARC alignment. Units and vendors that do not complete this work in advance may experience mail delivery failures once their domain moves to a Reject policy.

This page will be updated periodically to reflect:

  • Which domains have already transitioned to a DMARC policy of Reject
  • Upcoming domains scheduled for enforcement
  • Any additional guidance or remediation resources as they become available

We strongly encourage all domain owners, administrators, and service operators to review their sending infrastructure and coordinate with CUIT well in advance of their domain’s transition. Early validation and testing are critical to avoid unintended disruptions to legitimate email communications.

For questions, impact assessment, or assistance with DMARC compliance, please contact CUIT through the appropriate support channels.

FAQs: DMARC Enforcement and Third‑Party Mailing Services

(Mailchimp, Salesforce Marketing Cloud, Qualtrics, MailerLite, Constant Contact, etc.)

Once a domain is set to a DMARC policy of p=reject, any email that fails DMARC authentication will be rejected outright by receiving mail systems. This means that third‑party mailing platforms such as Mailchimp, Salesforce Marketing Cloud, Qualtrics, MailerLite, Constant Contact, and similar services will no longer be able to send email using a Columbia domain unless they are fully and correctly authenticated.

If your service is not properly configured for DMARC alignment, messages may:

  • Fail to be delivered
  • Be rejected by recipient mail servers without reaching inboxes or spam folders
  • Generate delivery or authentication errors within the third‑party platform

DMARC Reject is designed to prevent domain spoofing and phishing, but it also enforces strict requirements on legitimate senders.

For email to pass DMARC under a Reject policy, at least one of the following must be true and aligned with the visible “From” domain:

  • SPF alignment:
    The third‑party service’s sending servers must be authorized in the domain’s SPF record and use the same domain in the return‑path.

OR

  • DKIM alignment (strongly recommended):
    The third‑party service must digitally sign outgoing messages using a DKIM key for the exact domain (or approved subdomain) shown in the “From” address.

Most large mailing platforms support DKIM signing, and CUIT strongly recommends DKIM over SPF‑only configurations for reliability and scalability.

If no action is taken:

  • Email sent from third‑party platforms using your Columbia domain will be rejected
  • Campaign emails may appear to send successfully within the platform but will not reach recipients
  • Business‑critical communications (announcements, surveys, newsletters, workflows) may silently fail
  • CUIT will not be able to bypass DMARC enforcement for individual senders once Reject is enabled

DMARC Reject is enforced at the receiving mail server level and cannot be overridden on a per‑message or per‑vendor basis.

You must ensure the third‑party service is properly authenticated and DMARC‑aligned before your domain moves to Reject. At a high level, this involves:

  1. Confirming the platform supports custom domain authentication
  2. Configuring DKIM signing using DNS records provided by the vendor
  3. Ensuring the “From” address uses an approved and authenticated domain
  4. Completing verification within the vendor’s interface
  5. Validating successful authentication before production use

Most vendors provide their own setup instructions. CUIT assistance may be required for DNS changes or policy review.

Please be advised that CUIT has already configured and authenticated two subdomains for use with Mailchimp. If you would like to use one of these approved subdomains, please submit a ticket to the Email Team and we will be happy to assist.

CUIT is unable to add Mailchimp authentication records to the top-level domain "Columbia.edu".

In most cases, no.

While SPF technically can satisfy DMARC, many third‑party platforms:

  • Use shared infrastructure
  • Modify return‑path domains
  • Rotate sending IPs frequently

These factors often cause SPF alignment to fail under a Reject policy. DKIM is the recommended and expected method for all third‑party senders.

Yes. In most cases, CUIT may recommend using a dedicated subdomain (e.g., mail.example.columbia.edu) for third‑party sending. This approach:

  • Limits blast radius
  • Simplifies authentication
  • Improves monitoring
  • Aligns with email security best practices

Subdomain usage must still meet full DMARC, SPF, and DKIM requirements. You will need to provide us the SPF and DMARC records from the external domains.

Yes, DMARC enforcement applies equally to:

  • Marketing emails
  • Surveys and forms (e.g., Qualtrics)
  • Automated notifications
  • Event registration systems
  • Workflow or application‑generated email

Any system sending mail using a Columbia domain must comply.

CUIT does not configure third‑party vendor platforms on behalf of departments. However, CUIT can:

  • Confirm whether a proposed authentication approach is acceptable
  • Assist with DNS records at the domain level
  • Help assess DMARC risk and readiness
  • Validate alignment concepts and policy compliance

Departments remain responsible for coordinating setup directly with their vendors.

This page will be updated periodically to indicate:

  • Domains that have already transitioned to Reject
  • Domains scheduled for upcoming enforcement
  • Key milestones and deadlines

Domain owners should monitor this page and begin remediation as early as possible.

If you use Mailchimp or any third‑party mailing platform and are unsure about your DMARC readiness, contact CUIT through the appropriate support channel as early as possible. Early engagement is strongly encouraged to avoid service disruptions.