Fix guide

How to Fix DMARC Alignment for Mimecast

Mimecast DMARC alignment requires configuring DKIM signing policies in the Mimecast administration console and publishing the provided DKIM TXT record to your DNS.

Why alignment fails

Without Mimecast DKIM DNS and correct SPF, outbound mail through Mimecast may not align.

Exact DNS records

DKIM TXT at selector._domainkey from Mimecast SPF: include:_netblocks.mimecast.com (verify for your tenant/region)

Step-by-step fix

Step 1 Mimecast Admin → Administration → Gateway → Policies → DNS Authentication
Step 2 Generate DKIM key for your domain in Mimecast
Step 3 Add DKIM TXT at selector Mimecast specifies
Step 4 Include include:_netblocks.mimecast.com in SPF as required
Step 5 Wait for verification in Mimecast
Step 6 Confirm public records with DNS Preflight

Verify alignment and DNS in your browser

Open DNS Preflight →

FAQ

Where is Mimecast DKIM configured?

Typically Administration → Gateway → Policies → DNS Authentication — exact labels may vary by console version.

How do I generate a Mimecast DKIM key?

Use the DKIM wizard in Mimecast Admin; publish the TXT record at the given selector._domainkey hostname.

What SPF include does Mimecast use?

Often include:_netblocks.mimecast.com — confirm in Mimecast documentation for your region.

How do I verify Mimecast DKIM?

Mimecast shows status when DNS is correct. DNS Preflight can read the published TXT.

Does Mimecast support DMARC p=reject?

Yes when alignment passes — monitor aggregate reports.