Back to blog

GoDaddy's DMARC address turns off Google reports

Google is the largest DMARC reporter. But it sends nothing while GoDaddy's address sits in the rua tag.

Published: October 02, 2026

A domain sent email every day. Yahoo reported on it. Microsoft reported on it. Google had sent a DMARC report every day for seven weeks, and then stopped.

Day one without a Google report looks like a delay. Day five looks like a problem. By day sixteen the DMARC dashboard showed a flat line where Google used to be, and the domain owner asked the obvious question: what broke?

The owner was sure of one thing. Nobody had touched the DNS.

First suspects: outage, delivery, syntax, policy

A Google outage. Reporters do go quiet, for hours or for days. The DMARC reporters status page answers this question in seconds. Google kept reporting on other domains every day of those sixteen days. Not an outage.

Lost reports. Reports lost on the way would hit other domains too. They didn't. Every Google report for every other domain arrived. Not delivery.

A broken record. One record at _dmarc, valid syntax, every address with its mailto: prefix. Yahoo and Microsoft read the same record and kept reporting. Not syntax.

The policy. This suspect looked guilty. The DMARC record had changed after all, on the exact day the Google reports stopped. The policy went from p=quarantine to p=reject. A stricter policy and a silent Google, on the same day.

But Google reports on p=reject domains all day long. And the record history clears the policy completely.

The clue in the record history

DmarcDkim.com's DNS monitoring had the answer on file. It checks the domain's DNS records every day, keeps every version of the DMARC record, and stamps each change with its date. The owner's memory said nothing changed. The monitoring said otherwise.

The September change touched more than the policy. The rua tag changed too: the owner's own mailbox was gone, and a new address had taken its place.

The DNS monitoring history for 2026 tells the rest:

Period (2026) Policy Addresses in rua Google reports

Until July 7

reject

DmarcDkim.com + GoDaddy

none

July 7 to July 10

none

DmarcDkim.com only

daily

July 10 to July 22

quarantine

GoDaddy address present

none

July 22 to September 10

quarantine

DmarcDkim.com + the owner's mailbox

daily

September 10 to September 27

reject

DmarcDkim.com + GoDaddy

none

Since September 27

reject

DmarcDkim.com only

daily

Read the policy column. Google reported under none, quarantine and reject, and went silent under quarantine and reject. The policy explains nothing.

Read the rua column. Every silent period has one address in it. No daily period has it. Three switches, three matches.

The culprit: GoDaddy's reporting address

mailto:dmarc_rua@onsecureserver.net

This is GoDaddy's default DMARC reporting address.

On September 27 the owner removed the address and left the rest of the record alone, p=reject included. Google's reports resumed from that same day and arrive daily since.

The usual explanation for a dead report address does not apply. An address on another domain needs that domain to publish a TXT record that accepts the reports. GoDaddy publishes one as a wildcard that covers every domain:

 

$ dig +short TXT example.com._report._dmarc.onsecureserver.net

 

"v=DMARC1"

Google Public DNS, Cloudflare and both GoDaddy nameservers return the same answer, over UDP and TCP. No CNAME, no duplicate record.

The DMARC specification handles each report address on its own: an address that fails the checks is skipped, and the others still get reports. Google breaks this rule for GoDaddy's address, and Google does not document it. Searches turn up no public report of the problem.

Every other domain shows the same

One domain could be a coincidence. The comparison below covers domains that report to DmarcDkim.com and actively send mail, so other providers report on them regularly.

Addresses in rua Google reports

DmarcDkim.com only

yes

DmarcDkim.com + another external address

yes

DmarcDkim.com + GoDaddy's address

never

A second DMARC service or the owner's own mailbox in the rua tag changes nothing. The policy changes nothing either, p=none included. Domains with several reports a day from other providers get not a single one from Google.

Where the address comes from

Since April 2025, GoDaddy adds this DMARC record to new domains bought through or moved to GoDaddy:

v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net;

GoDaddy plans to add it to older domains too. GoDaddy does not notify the owner, and the reports go to GoDaddy, not to the owner.

Add a report address without removing GoDaddy's, and the record looks like this:

v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com,mailto:dmarc_rua@onsecureserver.net; ...

And "nobody touched the DNS" proves nothing. This owner made no changes, yet the record changed on September 10. Anyone with DNS access, or a provider's automatic setup, can rewrite it. DNS monitoring caught the change the same day. Without that history, the policy change would have taken the blame, and the GoDaddy address would still be in the record.

Check and fix the domain

1. Rule out a reporter outage. Check the DMARC reporters status page first. If Google reports have stopped for every domain, the cause is an outage at Google, not the DMARC record. Wait it out.

2. Look up the DMARC record.

 

dig +short TXT _dmarc.example.com

Or run the free DMARC check. If the rua tag contains onsecureserver.net, the domain is affected.

3. Remove GoDaddy's address. Edit the TXT record at _dmarc. Delete mailto:dmarc_rua@onsecureserver.net from the rua tag. Leave everything else as it is, including the policy.

Before:

v=DMARC1; p=reject; rua=mailto:dmarc@example.com,mailto:dmarc_rua@onsecureserver.net; adkim=r; aspf=r

After:

v=DMARC1; p=reject; rua=mailto:dmarc@example.com; adkim=r; aspf=r

Nothing is lost: those reports go to GoDaddy, never to the domain owner.

4. Keep one record. Do not add a second DMARC record next to the old one. Two records at _dmarc invalidate the policy, and every provider ignores it.

5. Wait two days. Google sends reports once a day. Expect Google reports within 48 hours for any domain that sends mail to Gmail or Google Workspace.

6. Monitor the record. Turn on DmarcDkim.com DNS monitoring. It flags every change to the DMARC record, so a returning GoDaddy address shows up the day it lands, not weeks later. Then find out who changed the record and stop it.

Final note

A valid, authorized report address is no guarantee. For Google, the rua tag is not a list of independent destinations: one address decides for the whole record.

Three rules follow from this case:

  • Keep only report addresses someone reads. Every address in the rua tag carries risk for the others. GoDaddy's address carries the most and gives the domain owner nothing back.

  • Treat a silent reporter as a DNS question first. Rule out an outage on the DMARC reporters status page, then put the DMARC record history next to the report history. The day the reports stop is the day to look at in DNS.

  • Trust the record history, not memory. The owner remembered no change. DmarcDkim.com DNS monitoring had the change on file, with its date, and that history named the GoDaddy address as the cause instead of the policy.

Run the free DMARC check on every domain hosted at GoDaddy and remove the address wherever it appears. Then let DmarcDkim.com DNS monitoring track every change to the DMARC record and DMARC Analytics flag the next reporter that goes quiet.

Is your domain really protected?

Enter your domain to run a live DMARC check and see how easy it for others to spoof your domain.

No sign-up required. Safe to try on any domain.

More articles

Bulletproof emails with DMARC

Check domain and follow the instructions to nail down your DMARC configuration.
No expert knowledge needed!