What is DMARC alignment?

Updated 9 October 2026 · 5 min read

DMARC alignment means the domain that passed SPF or DKIM is the same as the domain in your From address, the one people see. An email only passes DMARC when at least one of those checks passes and aligns, so a pass for your email service's domain doesn't count.

Why DMARC needs alignment

Anyone can type your address into the From line of an email. SPF and DKIM prove an email came from a particular domain, but not necessarily yours:

  • SPF is a DNS record that lists the servers allowed to send email for a domain.
  • DKIM is a digital signature that proves an email came from a domain and wasn't changed on the way.

A scammer can pass SPF and DKIM for their own domain while showing yourbusiness.com in the From line. Alignment closes that gap: DMARC asks whether SPF or DKIM passed for the domain your readers actually see.

The three domains in every email

Each email carries up to three domains, and only one of them is on show.

DomainWhere it isChecked by
FromThe sender address people see, such as hello@yourbusiness.comDMARC, which compares the other two with it
Return-PathA hidden bounce address, also called the envelope sender or MAIL FROMSPF
DKIM d=The domain named inside the DKIM signatureDKIM

You can see all three in Gmail. Open an email, choose Show original from the three-dot menu, and look for the Return-Path line and the d= value in the DKIM-Signature header.

SPF alignment

SPF doesn't look at your From address at all. It checks the Return-Path domain's SPF record. SPF aligns when the Return-Path domain matches the From domain. Email sent from Google Workspace uses your own address as the Return-Path, so SPF aligns. Most email marketing services use their own bounce domain, something like bounces.emailservice.com, so SPF passes for them and doesn't align for you.

DKIM alignment

DKIM aligns when the d= domain in the signature matches the From domain.

Until you set up domain authentication, a service usually signs your email with its own domain. The signature passes, because it really is theirs, but it doesn't align. Once you set it up, the service signs with yourbusiness.com and DKIM aligns.

Relaxed vs strict alignment

How closely the domains must match is set in your DMARC record, with adkim for DKIM and aspf for SPF.

ModeTagWhat counts as a match for yourbusiness.com
Relaxed (the default)adkim=r, aspf=r, or no tagyourbusiness.com, or any subdomain such as send.yourbusiness.com
Strictadkim=s, aspf=sOnly yourbusiness.com exactly

Relaxed alignment compares the main domain, the part you registered. Google says relaxed alignment typically gives enough protection, and that strict alignment can send email from your own subdomains to spam or get it rejected. Many services send from a subdomain such as send.yourbusiness.com, which strict alignment fails. If your record has adkim=s or aspf=s and you didn't add it on purpose, remove it.

DMARC was updated in May 2026, when RFC 9989 replaced RFC 7489. Relaxed and strict alignment work the same way. What changed is how receivers find the main domain: by looking up the DNS tree rather than relying on a published list. For an ordinary domain like yourbusiness.com, that makes no difference.

Why SPF passes but DMARC fails

This is the most common alignment problem with third-party senders. Say you send a newsletter from hello@yourbusiness.com through an email service:

  1. The Return-Path is the service's bounce domain, so SPF is checked against the service's record. It passes.
  2. The service signs with its own domain, so DKIM passes too.
  3. Neither pass is for yourbusiness.com. DMARC fails.

The email looks fully authenticated, and inboxes may even show "via" and the service's domain next to your name. But Gmail and Yahoo require bulk senders to pass DMARC with an aligned domain. And if your DMARC policy is quarantine or reject, receivers are asked to junk or refuse that email.

Adding the service's include to your own SPF record doesn't fix this. SPF isn't checking your record, because the Return-Path isn't your domain.

How to fix alignment

You need one aligned pass. There are two ways to get it.

Make DKIM sign with your domain

Turn on domain authentication in each service that sends as you. The service gives you DNS records, usually CNAME or TXT records with _domainkey in the name, and from then on it signs your email with yourbusiness.com.

  • Google Workspace: generate a DKIM key in the Google Admin console and publish it at google._domainkey.
  • Mailchimp: add the two CNAME records at k2._domainkey and k3._domainkey.
  • Klaviyo: set up a branded sending domain.
  • Other services: look for "domain authentication" or "sender authentication" in their settings or help pages.

DKIM is the better route. It survives forwarding, where SPF usually fails, and Gmail and Yahoo require it for bulk senders anyway.

Use a custom return-path

Some services also let the Return-Path use a subdomain of yours, so SPF aligns too. Services name this differently:

  • SendGrid: domain authentication adds an em… CNAME record that does this as well as DKIM.
  • Amazon SES: set a custom MAIL FROM domain, such as bounce.yourbusiness.com, and add the MX and SPF records SES shows.
  • Postmark: add a Return-Path CNAME, pm-bounces.yourbusiness.com pointing to pm.mtasv.net.

Many services, Mailchimp among them, don't offer this. That's fine: aligned DKIM on its own is enough for DMARC.

How we check it

Send one test email to your private test address from each service you use. The report shows the From domain, the Return-Path domain SPF checked, the d= domain on each DKIM signature, and whether any of them aligned, taking account of relaxed or strict alignment in your DMARC record. You get a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and when alignment fails, the setup step that fixes it.

Checked against: Google Workspace Admin Help, Set up DMARC · Google Workspace Admin Help, Troubleshoot DMARC issues · RFC 9989, Domain-Based Message Authentication, Reporting, and Conformance (DMARC) · RFC 7489, Domain-based Message Authentication, Reporting, and Conformance (DMARC) · Amazon SES Developer Guide, Using a custom MAIL FROM domain · Postmark, Adding a custom Return-Path domain · Twilio SendGrid, How to set up domain authentication.

Questions people ask

Do I need both SPF and DKIM to align?

No. DMARC passes if either one passes and aligns. DKIM is the better one to rely on, because it survives forwarding and most email services can sign with your domain.

Should I use strict alignment?

Usually not. Relaxed is the default and Google says it typically gives enough protection. Strict alignment fails email from services that use a subdomain such as send.yourbusiness.com, which is how many of them are set up.

Will adding a service's include to my SPF record fix alignment?

Not if the service uses its own bounce domain. SPF is checked against that bounce domain, so your record isn't read at all. Set up domain authentication in the service so DKIM signs with your domain, or a custom return-path if it offers one.

Why does DMARC fail when I forward email?

Forwarding sends the email from a different server, so SPF usually fails. If the email also has an aligned DKIM signature that the forwarder didn't break, DMARC still passes. That is one more reason to rely on DKIM.