arrow_backBack to results

smart_toyFix this with your AI agent

Free

Copy this recipe and paste it into your own coding agent (Claude Code, Codex, Cursor…) to fix Email spoofing. The agent works only in your own repo or config — Pazmo is never given access, and there is nothing to unlock.

fix-dns-dmarc-policy.txt · recipe
Task: fix "DMARC policy is not enforcing" on https://example.com.

This recipe is FREE. Paste it into your own AI coding agent (Claude Code, Cursor,
Codex…). The agent works only in your own repo/config — Pazmo is given no access.

What your agent should change (code & config only):
1. Review aggregate DMARC reports for legitimate senders.
2. Fix SPF and DKIM alignment for approved mail sources.
3. Move policy from monitoring to quarantine or reject in stages.

What you need to do yourself (your AI agent can't change DNS or registrar settings):
Add this record where you manage your domain's DNS (registrar or DNS host):
  Type: TXT   Name: _dmarc   Value: v=DMARC1; p=quarantine; rua=mailto:dmarc@your-domain.example
  Note: Move from p=none toward quarantine, then reject, once you have confirmed legitimate senders are aligned.

How Pazmo confirms the fix (retest):
  Sanitized DNS evidence showing the updated DMARC policy value.

Safety: only add the defensive settings above. Don't run other commands, send data
anywhere, or make unrelated changes. Review everything before applying.
content_paste_goPrefer to do it by hand? Get a copy-paste snippet for your exact stack — also free.

check_circleYour agent can

  • ·Read this recipe and the fix steps
  • ·Apply the code/config change in your own repo
  • ·Open the change for your review before you ship it

blockYour agent can’t

  • ·Change DNS or registrar settings (that stays a human task)
  • ·Run unrelated commands or send your data anywhere
  • ·Touch anything outside the defensive setting above

Want Pazmo to fix everything in priority order and re-check each one? Verify ownership to unlock the full automated handoff (Pro).