Is there a way to enforce DMARC to fail/reject mail that doesn't pass BOTH DKIM and SPF?
We have been narrowing the number that are failing, but there are some domains in our aggregate (rua) report that are passing just DKIM and we would rather that they fail our DMARC because we don't recognize them.
The domains that we do recognize are fully-aligned.
Our end goal is that unless it is fully aligned (both DKIM AND SPF), the message will be rejected