▸case-05 Our marketing team wants our corporate logo to display alongside outgoing emails in major webmail clients by setting up Brand Indicators for Message Identification (BIMI). Detail the prerequisite steps, SVG image formatting constraints, VMC certificate procurement, and DNS TXT record structure needed for BIMI implementation. Format as an implementation guide. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 During DMARC alignment testing, our team noted that SPF passed at the IP level, but DMARC reported an alignment failure. Explain how SPF alignment is determined under DMARC rules, comparing the envelope Return-Path header with the RFC5322 From header. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 Our Chief Information Security Officer asks for a realistic total project timeline estimate for taking our complex enterprise (with 15 third-party mail senders) from zero DMARC protection to complete 100% p=reject enforcement without risking legitimate email loss. What realistic timeframe range should we present in the executive briefing? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 When starting a corporate DMARC enforcement project, some engineers want to publish a p=quarantine DNS record immediately on day 1 and then investigate which systems fail delivery. Explain why this approach is flawed and outline the mandatory pre-rollout steps that must occur in Weeks 1 through 4 before publishing any enforcement record. Format as an operational risk assessment. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 Our mail gateways frequently re-route and modify email headers for mailing lists, which breaks upstream SPF and DKIM signatures. We need to implement Authenticated Received Chain (ARC) per RFC 8617 to preserve authentication results across intermediate hops. Outline how to configure ARC seals, signature headers, and validation logic. Format as an engineering deployment guide. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 We are currently stepping up our DMARC enforcement percentage during the rollout. After increasing the pct tag value from 25% to 50%, how long should we wait and monitor aggregate reports before advancing to the next percentage step (75%)? Provide the recommended monitoring interval. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 I need to prepare a rollout plan for my team to secure our sending domains using DMARC. We have multiple third-party marketing tools and internal mailers sending on our behalf. Outline an end-to-end policy migration workflow that explains how to safely scale enforcement percentages, handle aggregate reports, and manage subdomains. Deliver this as an actionable implementation guide with specific milestones and ongoing maintenance procedures. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 After analyzing aggregate reports in monitoring mode for two weeks, we are ready to move into the quarantine phase. Many team members suggest jumping straight to p=quarantine at 100% enforcement immediately. What initial percentage configuration should we start with to safely test quarantine enforcement, and how is this configured in the record? Provide the record definition and rollout rationale. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 We are ready for Week 4 of our domain security project and need to publish our first DMARC record in DNS to begin collecting aggregate failure reports at dmarc@company.com without impacting mail delivery. What exact policy value and aggregate report tag structure should be placed in this initial record? Provide the complete raw DNS TXT record string. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 We are configuring DKIM alignment for our domain example.com. Outbound emails are signed with d=mail.example.com while the From header is example.com. Should we use relaxed or strict DKIM alignment, and what exact tag key-value pair represents relaxed alignment in the DNS record? Provide a concise specification. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We are planning to implement email anti-spoofing across our primary domain and need a comprehensive rollout strategy. Please create a multi-week project roadmap that details how to progress from initial discovery and alignment validation through partial enforcement up to complete blocking. Format the response as a structured phase-by-phase implementation schedule outlining specific activities and record configurations needed at each stage. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 Our domain has been running smoothly at p=quarantine with pct=100 for four weeks. Management wants to advance to full p=reject. Should we switch directly to p=reject without percentage tags, or apply a gradual percentage ramp? Provide the recommended initial DNS record for entering the reject phase. | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 We have deployed p=quarantine with pct=10 and monitored aggregate reports for 2 weeks with zero false positives. Detail the precise sequence of percentage step increases recommended before reaching full 100% quarantine enforcement. Format as a milestone schedule showing each target percentage. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 A third-party email provider signs our outbound messages with DKIM signature header d=thirdparty.com, while the email's From header displays user@ourcompany.com. Will this message pass DMARC alignment, and what must be changed so that DKIM passes DMARC alignment? Provide a technical analysis. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 We need to enforce strict TLS encryption for incoming SMTP connections using MTA-STS (RFC 8461) across our enterprise domains. Provide a technical project plan outlining how to publish the DNS TXT record for _mta-sts, configure the policy file served over HTTPS, transition through testing modes, and enable enforcement. Format as a step-by-step implementation guide. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 Our organization currently has no DMARC record published for our main domain, and management wants us to enforce full protection against domain spoofing. Can you provide a step-by-step operational checklist for transitioning our email infrastructure through monitoring, quarantine, and full rejection? Please organize the output into sequential operational phases, listing pre-requisites, step actions, and verification criteria for moving between levels. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 During our transition to p=reject at pct=50, a critical executive transactional service began failing alignment due to an unannounced vendor server change, causing legitimate business emails to drop. What is the standard emergency operational procedure to mitigate this business disruption while investigating? Detail the remediation step. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 We are setting up DMARC record reporting tags. Explain the operational difference between the rua tag and the ruf tag, including report frequency, format, and primary analytical use cases. Format as a technical comparison. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 We are deploying a DMARC record and deciding on failure reporting options (the fo tag). Some guide books recommend fo=0, while others suggest fo=1. We want forensic failure reports generated whenever either SPF or DKIM fails alignment, rather than waiting for both to fail simultaneously. What parameter value should be set for the fo tag in our TXT record? Provide a record specification snippet and explanation. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 We are configuring SPF for our domain email security. We have 12 third-party SaaS vendors that each ask us to add an 'include:' statement in our DNS TXT record. Many admins suggest just putting all 12 vendors into one long SPF record. Provide advice on whether this is acceptable under RFC 7208 standards and how to handle lookup constraints, formatted as an architectural recommendation. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 In our email authentication policy, our Return-Path header domain is transactional.example.com while our RFC5322 From header domain is example.com. We are deciding between relaxed and strict SPF alignment in our record. Explain how relaxed vs strict SPF alignment treats this specific scenario and specify which alignment value to configure in the record tag. Provide a technical explanation. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 We have successfully reached 100% reject enforcement on our root domain example.com. However, attackers might attempt to send spoofed emails using unmonitored subdomains like marketing.example.com or support.example.com. What specific DMARC record tag must be configured to explicitly enforce reject policy across all current and future subdomains? Provide the tag format and value. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 We have successfully achieved full p=reject enforcement across all company email domains. Describe the routine maintenance tasks required to maintain this state long-term, specifically specifying the recommended frequency for DKIM cryptographic key rotation. Provide an operational maintenance checklist. | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |