Blog · Dmarc

Why Your DMARC Reports Show Reject Records for Non-Existent Gov.uk Subdomains

Why Your DMARC Reports Show Reject Records for Non-Existent Gov.uk Subdomains

You open your DMARC aggregate report. You see a block of reject records. The From domain listed is something like _spf.gov.uk or api.gov.uk - a subdomain you have never heard of, do not own, and have never sent email from.

This looks alarming. In most cases it is not.

The gov.uk domain publishes a reject policy against all subdomains. When your DMARC monitor flags reject records for a non-existent gov.uk subdomain, it almost always means an unrelated sender failed DMARC against their own domain - and your aggregate report is picking up the downstream observation point. Here is how that works and how to tell whether what you are seeing is normal.

What the gov.uk DMARC record actually does

The _dmarc.gov.uk DNS record looks like this:


_dmarc.gov.uk. 300 IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@digital.cabinet-office.gov.uk"

The critical detail is that this record exists at the organizational domain level - not at individual subdomains. When a DMARC check runs against any subdomain of gov.uk, the verifier strips the subdomain label and looks up the DMARC record for the parent domain. So mail from anything.gov.uk checks against _dmarc.gov.uk.

This means the reject policy applies to every subdomain of gov.uk that does not have its own explicit override. If a sender somewhere in the world tries to send email with a From domain of _spf.gov.uk or application.gov.uk and that email fails DMARC - because the domain does not send mail, or because its DKIM or SPF setup is wrong - that failure triggers a reject under gov.uk's policy.

Your aggregate report captures it because your mail server was the destination that rejected it.

Why your DMARC report shows reject records for domains you do not own

DMARC aggregate reports are sent to the address listed in the From domain's DMARC record. When a message fails DMARC, the receiving server generates a report and sends it to the RUA address for the From domain.

Here is the part that causes the confusion. Your DMARC report shows what you rejected. The From domain on the rejected message determines whose policy applied. If the message had a From domain of _spf.gov.uk and you rejected it, your report records a reject for gov.uk - not for your own domain.

You are reporting on mail you rejected, not on mail that belongs to you. The From domain in your reject record is gov.uk's domain, because gov.uk's DMARC policy is the one that failed, not yours.

This is why you can receive reject records for domains you have never heard of. They do not belong to you. They belong to the sender whose domain failed DMARC - and your mail server correctly rejected it.

How to tell if the rejects indicate genuine spoofing versus normal DMARC behavior

Normal DMARC artifact indicators:

  • The source IP belongs to known legitimate sending infrastructure - government domains, established ESPs
  • The From domain is a non-existent gov.uk subdomain that has never legitimately sent email
  • The reject volume is low and consistent over time
  • The failure is DKIM or SPF failure for the gov.uk domain, not your own

Genuine spoofing indicators:

  • The source IP does not match any known government or legitimate sending infrastructure
  • The From domain is your own domain or a close imitation of it
  • The reject volume is suddenly increasing for a domain you actually own
  • The reject record shows your domain in the From field, not an unrelated domain

The key test: does the From domain in the reject record belong to you? If yes, investigate. If the From domain is a gov.uk subdomain you have never heard of, this is almost certainly a normal DMARC artifact - someone else's misconfiguration that your mail server correctly rejected.

What to do if you find genuine spoofing in your DMARC reports

If your aggregate report shows reject records where the From domain matches your own domain and the source IP is unfamiliar, treat it as a legitimate spoofing attempt. Here is what to do:

1. Identify the source IP range from the reject record

2. Check whether it falls within known legitimate ranges for your vendors or partners

3. If it does not, report the activity to your security team or the relevant CERT

4. For gov.uk spoofing specifically, you can report it to the UK National Cyber Security Centre (NCSC)

The gov.uk domain's strict DMARC policy is useful here: because they reject everything, your reject records for gov.uk-related source IPs give you a read on what infrastructure is being misused in spoofing campaigns. If a significant volume of rejects shows IPs from infrastructure not associated with gov.uk's own sending, that is a signal worth escalating.

How DMARC aggregate report monitoring helps you separate signal from noise

Reject records for non-existent subdomains are normal background noise in most DMARC aggregate reports. The real question is not whether they appear - it is whether their volume, source IP distribution, or target domain patterns are changing.

A DMARC monitoring tool that parses reject records, groups them by organizational domain, and tracks baseline volume over time makes this straightforward. You stop manually reviewing raw XML and start seeing patterns: normal baseline noise versus a spike that indicates a spoofing campaign against your domain is growing.

DMARCFlow's aggregate report monitoring automatically groups reject records by From domain, tracks source IP distributions per organizational domain, and surfaces anomalies - like a sudden increase in rejects for unfamiliar subdomains - so you can investigate the ones that actually matter.

FAQ

Did someone just try to spoof my domain using gov.uk?

No. If the From domain in the reject record is a gov.uk subdomain (not your own domain), it means you rejected a message that failed DMARC for the gov.uk domain. Gov.uk's reject policy caught it. Your domain was the destination, not the target.

How does the _dmarc.gov.uk record affect my domain?

It does not. Your DMARC policy applies to your From domain. Gov.uk's DMARC policy applies to theirs. A reject record showing a gov.uk subdomain in your aggregate report simply means you correctly rejected a message that violated gov.uk's policy.

Should I be concerned about these reject records?

In almost all cases, no. They are normal DMARC artifact. The exception: if the From domain matches your own domain and the source IP is unfamiliar, that may indicate spoofing of your domain and warrants investigation.

Related:

  • [Why big companies still do not use DMARC properly (and who is on the Wall of Shame)](/)
  • [How to route DMARC aggregate reports to a third-party aggregation service without direct email delivery](/)