I just enabled DMARC reporting and am looking through my first batch of entries (actually, just one entry). One thing caught my eye -- an SPF failure due to mismatched sender IP address (209.58.146.193), which resolves to imap1.us.opalstack.com.
<row>
<source_ip>209.58.146.193</source_ip>
<count>1</count>
<policy_evaluated>
<disposition>none</disposition>
<dkim>pass</dkim>
<spf>fail</spf>
</policy_evaluated>
</row>
I'm not sure why this IP would be sending an email from my domain. I did personally only send one email during that period, was that it? I send through gmail authenticated to smtp.us.opalstack.com. My SPF record checks out I think:
v=spf1 include:spf.opalstack.com include:_spf.google.com -all
That IMAP IP address is not in the spf.opalstack.com set of values, FWIW.
Any ideas?