Uploaded image for project: 'Jira Service Management Cloud'
  1. Jira Service Management Cloud
  2. JSDCLOUD-5614

JSD Notification were not sent out due to failed DMARC/Marked as SPAM. Add option to control the Reply-To: header in Jira Cloud

    • 586
    • 10
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Update from Product team (9th December 2021)

      Hey all,

      We are excited to announce that this feature has now been rollout out to all users.

      You can learn more here.

      We would love to hear your feedback.

      Cheers,

      Ben

      Emails from JSD that was sent out using domain other than atlassian.net is rejected by DMARC.

      Both SPF and DKIM checks are performed against the atlassian.net domain. So as far as DMARC is concerned no relevant validation has taken place for the domain and therefore got rejected.

      Update : Upon further investigation it looks like DMARC is not compatible with the custom email address setting in Jira Cloud. DMARC explicitly check that the domain in the From: header matches those that pass in the DKIM-Signature: header.

      This is further corroborated by this FAQ entry on the dmarc.org website. At this time there is no option to control the Reply-To: header in Jira Cloud. This option need to be added to in the Jira product and is raised with this feature request.

      The following workaround is suggested for affected instance with this limitation.

      Workaround :

      1. Whitelist IP range from this https://confluence.atlassian.com/cloud/atlassian-cloud-ip-ranges-and-domains-744721662.html
      2. Use From: address the default <user>@<instance>.atlassian.net email address

            [JSDCLOUD-5614] JSD Notification were not sent out due to failed DMARC/Marked as SPAM. Add option to control the Reply-To: header in Jira Cloud

            BK Paton added a comment -

            55ad25be08db once you domain as been added in Atlassian Administration you need to ensure it has all green ticks. 

            Once this is done, you can create an email address for the admin and associate it with a site. 

            The final step is associating it with a project in the Project Administration > Notifications page. 

            Only at this point will the email notifications from that project be DMARC compliant. 

            Let me know how you go.

            BK Paton added a comment - 55ad25be08db once you domain as been added in Atlassian Administration you need to ensure it has all green ticks.  Once this is done, you can create an email address for the admin and associate it with a site.  The final step is associating it with a project in the Project Administration > Notifications page.  Only at this point will the email notifications from that project be DMARC compliant.  Let me know how you go.

            @benjamin Paton, 

            We have all the required entries done however email are still not DMARC compliant.

            our CNAME entry doesn't end with . is that the reason why its failing 

            Mahesh Belagali added a comment - @benjamin Paton,  We have all the required entries done however email are still not DMARC compliant. our CNAME entry doesn't end with . is that the reason why its failing 

            BK Paton added a comment -

            Some domain providers will append it for you. Seems like yours might be in this group. Feel free to leave it off and it should work fine. Let us know if you have issues.

            BK Paton added a comment - Some domain providers will append it for you. Seems like yours might be in this group. Feel free to leave it off and it should work fine. Let us know if you have issues.

            I've tried to set this up, but our DNS provider's system does not support adding CNAMEs ending in a .

            Is it really intentional that they end in a . or is that a mistake somehow? It looks wrong...

            Jens Bech Madsen added a comment - I've tried to set this up, but our DNS provider's system does not support adding CNAMEs ending in a . Is it really intentional that they end in a . or is that a mistake somehow? It looks wrong...

            BK Paton added a comment -

            Hey all,

            We are excited to announce that this feature has now been rollout out to all users.

            You can learn more here.

            We would love to hear your feedback.

            Cheers,

            Ben

            BK Paton added a comment - Hey all, We are excited to announce that this feature has now been rollout out to all users. You can learn more here. We would love to hear your feedback. Cheers, Ben

            Thanks @Eric Byrd

            In fact our 6 domains are verified since 1 year, when we started our Atlassian instance!

            Let me insist, step 5 in your email (which is the same advertised at the public link) is not available to me

            5.Once DNS is cleared, click the Email addresses link on the Settings -> Emails page and add your addresses.

            https://imgur.com/a/c4igGaw 

            There is no emails options available under settings

            Kind regards,

            Nicola Guarino

            Nicola Guarino added a comment - Thanks @Eric Byrd In fact our 6 domains are verified since 1 year, when we started our Atlassian instance! Let me insist, step 5 in your email (which is the same advertised at the public link) is not available to me 5.Once DNS is cleared, click the Email addresses  link on the  Settings -> Emails  page and add your addresses. https://imgur.com/a/c4igGaw   There is no emails options available under settings Kind regards, Nicola Guarino

            Nick Green added a comment -

            Nope, not had to verify the settings at all since it started working.

            Nick Green added a comment - Nope, not had to verify the settings at all since it started working.

            Luke Calkins added a comment - - edited

            Anyone else having to re-verify their DNS every few days?

            Luke Calkins added a comment - - edited Anyone else having to re-verify their DNS every few days?

            Anthony Kylitis added a comment - - edited

            I too do not have the Settings > Email option.

            Do we have to be part of the test group to have that? I do have the original DNS records that were required setup along with a "verified" domain.

            Please advise us Benjamin.

            Anthony Kylitis added a comment - - edited I too do not have the Settings > Email option. Do we have to be part of the test group to have that? I do have the original DNS records that were required setup along with a "verified" domain. Please advise us Benjamin.

            Nick Green added a comment -

            Yep, you should receive an email from Benjamin Paton, or maybe someone else from Atlassian stating that you're site has DMARC enabled.

            Good luck!

            Nick Green added a comment - Yep, you should receive an email from Benjamin Paton, or maybe someone else from Atlassian stating that you're site has DMARC enabled. Good luck!

              7ad1551c39c0 BK Paton
              nmuhi Nazri Muhi (Inactive)
              Votes:
              280 Vote for this issue
              Watchers:
              255 Start watching this issue

                Created:
                Updated:
                Resolved: