Why Callie couldn't authenticate your email
When you contact Callie by email, we verify that the message came from the address shown in the "From" field. If this check fails, we can't process your message. This protects you and others from email spoofing.
This article explains why your email wasn't authenticated and how to fix it.
What is email authentication?
Email authentication uses special records on your domain to prove that you sent an email. Think of it like a digital signature for your domain. It tells email systems: "Yes, I sent this message."
Callie checks three authentication methods:
- SPF (Sender Policy Framework): Tells email systems which servers can send emails from your domain
- DKIM (DomainKeys Identified Mail): Adds a signature to each email to prove it hasn't been changed
- DMARC (Domain-based Message Authentication, Reporting and Conformance): Combines SPF and DKIM to set rules for failed authentication checks
If any check fails, your domain may not be set up to send verified emails. This is common with unconfigured Google Workspace and Microsoft 365 accounts.
Why this matters
Email spoofing lets attackers trick people by pretending to be someone else. By checking authentication records, Callie makes sure messages really come from your email address. This protects you and the people you email.
How to fix it
Set up or verify the authentication records for your email domain. Steps vary depending on whether you use Google Workspace or Microsoft 365.
For Google Workspace
Google Workspace usually has basic authentication set up, but you may need to verify your records:
- Go to the Google Admin console
- Select Apps → Google Workspace → Gmail
- Find the Authenticate email section
- Follow Google's guide to verify your DKIM, SPF, and DMARC setup
Helpful resources:
For Microsoft 365
You must set up authentication records in your domain provider's control panel:
- Go to the Microsoft 365 admin center
- Select Settings → Domains
- Select your domain
- Check the DNS records section for missing SPF, DKIM, or DMARC records
- Add any missing records through your domain provider's DNS settings
Helpful resources:
For other email providers
If you use a different provider, check their documentation for setting up SPF, DKIM, and DMARC records.
What happens next
After you set up authentication records for your domain:
- DNS changes take 24 to 48 hours to spread across the internet
- After that, emails from your domain should pass authentication checks
- You can contact Callie again without authentication errors
Note
If you still have problems after 48 hours, report the issue and include your email address and the time you sent the message. Our team can help.