Add the DKIM CNAME records from your Lumail domain page so mail is signed with a 2048-bit aligned key.
You got DKIM is missing, failed, or weak. Receiving servers cannot authenticate the message with DKIM, or the key is too weak.
Without DKIM (and alignment), DMARC cannot pass on the DKIM path.
Open Domains → the failing domain. Copy the DKIM CNAME rows exactly. Lumail issues three CNAMEs:
| Type | Host | Value |
|---|---|---|
| CNAME | TOKEN._domainkey | TOKEN.dkim.amazonses.com (region-specific host from the page) |
Do not invent tokens. Do not turn them into TXT records. Do not flatten the CNAME to an A/AAAA.
If the domain page shows Legacy Easy DKIM, keep those records; do not mix them with a second DKIM setup on the same name.
_domainkey on this sending domain.DKIM must stay published. Deleting a CNAME later reopens this alert and will fail DMARC alignment for Lumail mail.