Biz-Ai-DMARC / Guides
DMARC alignment
A message can pass SPF and DKIM and still fail DMARC. Alignment is why, and it is the first thing to understand when a legitimate service shows up as failing in your reports.
The problem
Every email has two From addresses
The header From is the address your recipient sees. The envelope sender (also called the Return-Path or MAIL FROM) is a separate address used behind the scenes for bounces, and nobody sees it.
SPF checks the envelope sender, not the visible From. DKIM checks whichever domain signed the message, shown as d= in the signature. Neither check, on its own, says anything about the address the recipient reads.
So a spammer can send from their own server, with their own envelope sender and their own DKIM key, pass both checks, and put your domain in the From line. Alignment closes that gap.

The rule
What aligned means
SPF alignment
SPF passes and the envelope sender domain matches the header From domain.
DKIM alignment
A DKIM signature verifies and its d= domain matches the header From domain.
DMARC passes when either one is aligned
One aligned pass is enough. That is why DKIM matters most: it survives situations where SPF breaks, as the next sections show.
Relaxed or strict
How close is a match?
Relaxed (the default, adkim=r and aspf=r) accepts any domain in the same organization. bounces.example.com aligns with example.com, and so does mail.example.com.
Strict (adkim=s, aspf=s) demands an exact match. bounces.example.com no longer aligns with example.com.
Relaxed is right for almost everyone. Strict mode mostly breaks legitimate services that bounce through a subdomain, and adds little protection unless someone outside your organization controls one of your subdomains, for example one delegated to a vendor.
What counts as the same organization
The “organizational domain” is the part you registered: example.com, or example.co.uk. The 2015 standard found it with a public list of domain suffixes. RFC 9989 (2026) finds it by walking up the DNS tree and looking for DMARC records, which also lets a large organization mark where its own boundaries are.
In your reports
Why legitimate mail fails alignment
- A service using its own bounce domain. A newsletter or billing platform sends with its own envelope sender, so SPF passes for their domain, not yours. Fix: have the service sign with DKIM on your domain (usually a CNAME or TXT record they give you), or set a custom Return-Path on your domain.
- A service signing DKIM with its own domain. The signature verifies but
d=is theirs. Fix: turn on “custom domain” or “domain authentication” in the service so it signs as you.
- Forwarding. When a message is forwarded, it arrives from the forwarder’s server, so SPF fails. DKIM usually survives, because the message itself is unchanged. This is why every source should sign with DKIM.
- Mailing lists. Lists often add a footer or change the subject, which breaks the DKIM signature. Many lists now rewrite the From address to their own domain to avoid this. ARC, a newer standard, lets a list vouch for the checks it saw on arrival.
Keep reading
More guides and free tools
Guides
- DMARC record tags: Every tag in a DMARC record, what it does and what to set it to.
- SPF record syntax: Mechanisms, qualifiers and the 10 DNS lookup limit.
- DMARC glossary: The terms used in records and reports, in plain words.
- Email authentication standards: The IETF documents that define SPF, DKIM and DMARC, with links to the source.
Free tools
- DMARC record generator: build a record for the current standard.
- DMARC report viewer: read an aggregate report as a table, in your browser.
- Biz-Ai-DMARC: reports collected, summarized and alerted on for you.
Tell us what is not working
A 30-minute call, no pitch deck. We will tell you what we would do first, and whether we are the right people to do it.