Skip to main content
Harun_Rashid
Level 1
September 21, 2026
Solved

Urgent: Marketo Emails Failing SPF/DKIM Authentication at Google Gmail – Request for Investigation

  • September 21, 2026
  • 3 replies
  • 61 views
 

Harun Rashid <harun.rashid@globallogic.com>

 

Attachments10:08 AM (24 minutes ago)
 
 
 
 
 
to Marketo, Marketo
 
 
 
 
 
 
Hello Marketo Support Team,

We are experiencing an email deliverability issue where emails and notification alerts sent through our Marketo instance are landing in the Spam folder for GlobalLogic recipients.
We have already reviewed and confirmed that the Marketo email authentication and sending configurations are set up correctly.
Issue Observed
Based on the email header analysis:
  • SPF and DKIM pass at the Mimecast receiving gateway.
  • Google Gmail subsequently reports SPF failure and DKIM body hash verification failure.
  • The email is routed through Mimecast before reaching Google Gmail.
  • Recipients are also seeing a warning that globallogic.com could not verify that it actually sent the message.
Request for Marketo Investigation
Could you please investigate this issue from the Marketo platform and email-sending infrastructure side?
We would like your team to specifically check:
  • Whether there is any possibility that the email content, headers, DKIM signatures, or other message attributes generated by Marketo are contributing to the authentication failures observed at Google Gmail.
  • Whether any known Marketo email delivery or DKIM signing issues could cause the DKIM body hash to fail after the email passes through the receiving gateway.
  • Whether the Marketo sending infrastructure or email generation process could be contributing to the SPF/DKIM discrepancies observed between Mimecast and Google.
  • Whether there are any known issues, recommended configurations, or platform-level fixes related to Marketo emails being delivered to Spam when routed through Mimecast to Google Gmail.
Expected Resolution
Please review the attached email header and help us determine whether any Marketo-side issue is contributing to this problem.
If the issue is not originating from Marketo, please help us confirm that based on your investigation and advise whether there are any specific Marketo-side changes or recommendations we should follow.
We would appreciate your urgent assistance, as this issue is affecting both email testing and notification alerts across the GlobalLogic domain.
Attachments: Full email header and screenshot of SPF/DKIM authentication results.
Thank you for your support.
 
 
 
Best Regards,
 
Harun Rashid    
Best answer by sandy_logitech

There’s nothing wrong with Marketo nor with your instance’s Marketo technical config. The problem lies in the Mimecast config.

 

First, SPF is immaterial in your case because you do not have a branded envelope sender. The SPF record for globallogic.com is never checked. (This is in fact the case for every Marketo instance; you only need SPF if you have a branded envelope, and even then it’s the envelope sender subdomain that needs the SPF record, not the main domain.)

 

Second, your DKIM signature as assembled by Marketo is valid for From: addresses @globallogic.com.

 

Sounds like Mimecast alters signed headers on their way to Gmail, which by design breaks Gmail’s DKIM check. And of course the source IP being a Mimecast IP means it will fail Gmail’s SPF check for potomac1050.mktomail.com (your non-branded envelope sender domain). Again, these are both by design. If your email did not fail these checks, that would be a problem!

 

You need to configure Gmail to trust emails relayed through Mimecast, leaving email security to Mimecast itself.

3 replies

Harun_Rashid
Level 1
September 21, 2026

 

sandy_logitech
User Group Leader
sandy_logitechUser Group LeaderAccepted solution
User Group Leader
September 21, 2026

There’s nothing wrong with Marketo nor with your instance’s Marketo technical config. The problem lies in the Mimecast config.

 

First, SPF is immaterial in your case because you do not have a branded envelope sender. The SPF record for globallogic.com is never checked. (This is in fact the case for every Marketo instance; you only need SPF if you have a branded envelope, and even then it’s the envelope sender subdomain that needs the SPF record, not the main domain.)

 

Second, your DKIM signature as assembled by Marketo is valid for From: addresses @globallogic.com.

 

Sounds like Mimecast alters signed headers on their way to Gmail, which by design breaks Gmail’s DKIM check. And of course the source IP being a Mimecast IP means it will fail Gmail’s SPF check for potomac1050.mktomail.com (your non-branded envelope sender domain). Again, these are both by design. If your email did not fail these checks, that would be a problem!

 

You need to configure Gmail to trust emails relayed through Mimecast, leaving email security to Mimecast itself.

sandy_logitech
User Group Leader
User Group Leader
September 23, 2026

​@Harun_Rashid please return to your thread and check replies.