Messages are being rejected by GMail with DMARC failures. Most of the messages are from well known senders such as Google, Microsoft, and the USDA. The senders' DKIM is in order and we have correct DMARC, SPF and DKIM settings with respect to our DNS. Gateways are in place per the documentation. GMail extra spam checks are turned off. Here's a rejection of the Sophos Central welcome email:
Confirm you have configured the gateways correctly
https://docs.sophos.com/central/Customer/help/en-us/ManageYourProducts/EmailSecurity/SophosGateway/ExternalServices/ConfigureGSuite/index.html#add-your…
https://docs.sophos.com/central/Customer/help/en-us/ManageYourProducts/EmailSecurity/SophosGateway/ExternalServices/ConfigureGSuite/index.html#add-your-domain-and-verify-ownership
According to gmail article https://support.google.com/a/answer/60730?hl=en
"Set up the inbound gateway setting to identify the gateway’s IP address or range of addresses. Gmail doesn't do SPF authentication for messages sent from IP addresses in the Gateway IPs list. The inbound gateway should do DMARC checks. DMARC authentication is bypassed for incoming messages from listed hosts."
So confirm that the correct IP's are on the list and that the email comes from that IP
If these are correct then the question becomes why is gmail checking this?
I have double and triple-checked this and the only solution is to add each sender with a DKIM of "-all" who is rejected to the Gateways list. Google's support seems to not be able to see an issue with this, describing the behavior as normal. My solution, for now, is to disable Smart Banners for this tenant and rely on changing the Subject line.
Please ask google support to check your Gateway IP list in google workspace The email that fails DMARC does if come from one of those IP's? If so according to their documentation referenced above they should not be doing DMARC. I cannot see how this can be normal behavior if their document says it should not be doing this. It say inbound gateway should do DMARC checks, which is Sophos Central Email.