DMARC alignment: relaxed vs strict
DMARC passes only when SPF or DKIM passes for a domain matching the From address. What alignment means, relaxed vs strict, and how to fix alignment failures.
Updated September 30, 2026
DMARC alignment means the domain that passed SPF or DKIM matches the domain in the visible From address. For SPF, the envelope sender (RFC5321.MailFrom, shown as Return-Path) is compared with the header From. For DKIM, the signature’s d= domain is compared with it. Relaxed alignment, the default, only needs the same organizational domain; strict alignment needs an exact match. A message passes DMARC if at least one of SPF or DKIM passes and aligns.
Why DMARC needs alignment
SPF and DKIM were designed to authenticate a domain, not the From address. Anyone can send mail with Return-Path: x@attacker.example, publish SPF for attacker.example, sign with d=attacker.example, and put From: ceo@example.com in the header. Both checks pass, for the attacker’s domain. Alignment is the rule that throws those passes away because they don’t belong to the domain the recipient sees.
SPF alignment: Return-Path vs From
SPF authenticates the domain in the SMTP MAIL FROM command, which receivers record as the Return-Path header. For SPF to count toward DMARC, SPF must pass and that domain must align with the header From domain (RFC5322.From). Look for both in the delivered message:
Return-Path: <bounce-7781@bounce.example.com>
From: Example Billing <billing@example.com>
Authentication-Results: mx.receiver.example;
spf=pass smtp.mailfrom=bounce.example.com;
dkim=pass header.d=example.com;
dmarc=pass header.from=example.comDKIM alignment: d= vs From
DKIM authenticates the domain in the signature’s d= tag (shown as header.d in Authentication-Results). For DKIM to count, the signature must verify and d= must align with the From domain. If a message has several signatures, one aligned passing signature is enough. The i= tag and the selector don’t matter for alignment.
Relaxed vs strict alignment
| Mode | Rule | Example with From: example.com |
|---|---|---|
| Relaxed (r) | Both domains have the same organizational domain. | example.com, mail.example.com and a.b.example.com all align. |
| Strict (s) | The domains are identical. | Only example.com aligns. mail.example.com doesn’t. |
The organizational domain is the registered domain: one label below a public suffix. For news.example.com it’s example.com; for shop.example.co.uk it’s example.co.uk, because co.uk is a public suffix. RFC 7489 finds it with the Public Suffix List. RFC 9989, the updated DMARC standard published in May 2026, replaces that with a DNS tree walk that looks for DMARC records up the domain’s labels, which gives the same answer for normal domains.
The adkim and aspf tags
You choose the mode per mechanism in your DMARC record. Both default to relaxed, so leaving them out is the same as writing adkim=r; aspf=r.
v=DMARC1; p=reject; rua=mailto:reports@example.com
v=DMARC1; p=reject; rua=mailto:reports@example.com; adkim=s; aspf=sAlignment examples
Each row assumes SPF passes for the Return-Path domain and DKIM verifies for the d= domain.
| Header From | Return-Path domain | DKIM d= | Relaxed result | Strict result |
|---|---|---|---|---|
example.com | example.com | example.com | Pass (both align) | Pass (both align) |
example.com | bounce.example.com | example.com | Pass (both align) | Pass (DKIM only) |
example.com | bounce.example.com | none | Pass (SPF aligns) | Fail |
example.com | mail.esp.example | mail.example.com | Pass (DKIM aligns) | Fail |
news.example.com | news.example.com | example.com | Pass (both align) | Pass (SPF only) |
example.com | mail.esp.example | esp.example | Fail | Fail |
shop.example.co.uk | example.co.uk | other.co.uk | Pass (SPF aligns) | Fail |
The second-to-last row is the one that catches most people: the message is fully authenticated, but only for the email platform’s domain, so DMARC fails.
Why email platforms fail alignment by default
Marketing, CRM and transactional platforms send from their own servers and need bounces to come back to them. Out of the box, most set the Return-Path to their own domain and many sign DKIM with their own domain too. Both checks pass, neither aligns, and DMARC fails. At p=none you only see this in reports. At p=reject the mail disappears.
Most platforms have a “domain authentication” or “sender domain” setup that fixes it with two changes:
- Custom DKIM. Publish the platform’s DKIM record (usually a CNAME) under your domain, so it signs with
d=example.com. This alone makes DMARC pass under relaxed alignment. - Custom return-path. Point a subdomain like
bounce.example.comat the platform (usually a CNAME or MX plus TXT), so the envelope sender is your subdomain and SPF aligns in relaxed mode.
| Host | Type | Value |
|---|---|---|
<selector>._domainkey | CNAME | <DKIM target from the platform>Selector and target come from the platform’s dashboard. |
bounce | CNAME | <return-path target from the platform>Some platforms use MX and TXT records here instead. |
Setup guides for specific platforms, such as SendGrid, Mailchimp and Amazon SES, give the exact steps.
Check your alignment settings
See your DMARC record’s adkim and aspf modes, plus SPF and DKIM for your domain, with the fixes to make.
Alignment, forwarding and mailing lists
Forwarding changes which checks can still pass. When a message is forwarded, the forwarder’s IP isn’t in your SPF record, so SPF fails (or, if the forwarder rewrites the envelope sender, passes for the forwarder’s domain, which doesn’t align). The DKIM signature usually survives untouched, so the message still passes DMARC on DKIM alignment.
Mailing lists are harder. A list that adds a subject prefix or footer breaks the DKIM signature, and it resends from its own servers, so neither mechanism aligns. Many lists work around this by rewriting the From address to the list’s own domain (“Jane via Team List”). Some receivers also use ARC headers from trusted intermediaries to accept such mail. That’s why some failures in your reports come from mail you really sent, and why a small amount of failing forwarded mail is normal at p=reject.
Should you use strict alignment?
Usually not. Relaxed alignment already stops outsiders, because only you control DNS under your organizational domain. Strict mode mainly breaks your own mail: platforms that use a return-path subdomain, subdomain senders signing with the parent domain, and anything else that isn’t an exact match. Consider strict only if you delegate subdomains to parties you don’t trust to send as the parent domain, and check your aggregate reports first. DMARC Dojo breaks your aggregate reports down by sending source with SPF and DKIM results for each, which is where you’d spot what strict mode would break.
More causes and fixes are in why DMARC fails. For the underlying protocols see what SPF is and what DKIM is.
Frequently asked questions
Do both SPF and DKIM need to align?
No. DMARC passes if either one passes and aligns. Aim for both, so a forwarded message still passes on DKIM and a broken signature still has SPF to fall back on.
What does “SPF pass, DMARC fail” mean?
SPF passed for a domain that doesn’t match your From domain, usually a platform’s bounce domain, and DKIM either failed or was signed by another domain too. Set up custom DKIM for that sender.
Does a subdomain align with its parent domain?
Yes, in relaxed mode. d=mail.example.com aligns with From: you@example.com, and the reverse is also true. In strict mode neither does.
Where do I see alignment results?
In the Authentication-Results header of a received message, and in your DMARC aggregate reports, which show the SPF and DKIM domains for each source. The DMARC report analyzer reads report files for you.
Does the DKIM selector affect alignment?
No. Only the d= domain is compared with the From domain. The selector just tells receivers where to find the key.