Fix guide
How to Fix DMARC Alignment for Mimecast
Mimecast DMARC alignment requires configuring DKIM signing policies in the Mimecast administration console and publishing the provided DKIM TXT record to your DNS.
Why alignment fails
Without Mimecast DKIM DNS and correct SPF, outbound mail through Mimecast may not align.
Exact DNS records
DKIM TXT at selector._domainkey from Mimecast
SPF: include:_netblocks.mimecast.com (verify for your tenant/region)
Step-by-step fix
Step 1 Mimecast Admin → Administration → Gateway → Policies → DNS Authentication
Step 2 Generate DKIM key for your domain in Mimecast
Step 3 Add DKIM TXT at selector Mimecast specifies
Step 4 Include include:_netblocks.mimecast.com in SPF as required
Step 5 Wait for verification in Mimecast
Step 6 Confirm public records with DNS Preflight
Verify alignment and DNS in your browser
Open DNS Preflight →FAQ
Where is Mimecast DKIM configured?
Typically Administration → Gateway → Policies → DNS Authentication — exact labels may vary by console version.
How do I generate a Mimecast DKIM key?
Use the DKIM wizard in Mimecast Admin; publish the TXT record at the given selector._domainkey hostname.
What SPF include does Mimecast use?
Often include:_netblocks.mimecast.com — confirm in Mimecast documentation for your region.
How do I verify Mimecast DKIM?
Mimecast shows status when DNS is correct. DNS Preflight can read the published TXT.
Does Mimecast support DMARC p=reject?
Yes when alignment passes — monitor aggregate reports.