Good morning Atlassian Community,
We enabled DMARC protecting for our JSM site roughly a year ago, and it... works, I guess. One of the things that we've struggled with is having a org friendly name where users can send mail to, ex. test@myorg.com. We use Microsoft for our org mail. I will also preface this by stating that I am by no means an expert in mail.
We have a process setup where we have a Shared Mailbox in our org that users send to, that then forwards the mail to the appropriate atlassian.net project. That works great for addresses for users with our domain, gmail.com, yahoo.com, and some other addresses. However, legitimate emails going through this process are failing DMARC when hitting JSM after they have been forwarded by the Shared Mailbox, with hotmail.com, outlook.com, and some others always failing the DMARC check after forwarding.
I know that you can create an OAuth connection to an account within the mail settings per JSM project, but our org is hesitant to allow login and mailbox enabled accounts for this intent with our current policies.
Something I did read, was that there's this thing called ARC validation, which I'm hoping that Atlassian will implement for their DMARC checks in the near future.
I want to know if anyone else has figured out a solution, on the JSM or Microsoft side, that still allows enforcing DMARC but not failing entire domains. If you have also struggled with this, feel free to chime in. Or even if you have an "unofficial" solution, we're open to it.
Thanks!
Brandon