DMARC Identifier Alignment

DMARC Identifier Alignment

DMARC Identifier Alignment

DMARC identifier alignment ensures that the domains authenticated by SPF and/or DKIM are aligned with the domain visible to recipients in the Header From field.

Email users rely on the From address shown in their email client to determine who sent a message. However, SPF and DKIM authenticate different domains by default, not the Header From domain. This can result in a situation where the authenticated domain does not match what the user sees. DMARC solves this problem through identifier alignment.

Header From vs Mail From

The Header From domain is the domain shown in the visible From address of an email. This is what recipients see in their inbox.

The Mail From domain (also known as the Return-Path, Envelope From, or bounce address) is used for message delivery and bounce handling. It is not visible to end users. SPF authentication is performed against the Mail From domain, not the Header From domain.

Because these domains can be different, an email may pass SPF or DKIM authentication but still fail DMARC if the authenticated domain is not aligned with the Header From domain.

How DMARC Alignment Works

DMARC checks alignment as follows:

  • SPF alignment compares the Mail From domain with the Header From domain

  • DKIM alignment compares the DKIM signing domain (d=) with the Header From domain

If either SPF or DKIM passes and the authenticated domain is aligned with the Header From domain, DMARC passes.

DMARC Alignment Modes

DMARC supports two alignment modes:

Strict alignment
The authenticated domain must exactly match the Header From domain.

Relaxed alignment
Subdomains of the same organizational domain are considered aligned.

    • Related Articles

    • Can We Setup DMARC Using SPF?

      Yes, you can set up DMARC without DKIM and even if you only have DMARC and SPF setup. In cases where the DKIM check fails, DMARC authentication is dependent on the SPF check and SPF identifier alignment, which works but is not that optimal. DMARC ...
    • What Is DMARC?

      DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol introduced in 2012 to reduce the risk of email-based cyberattacks such as phishing, spoofing, and domain impersonation. DMARC is considered an ...
    • How Smart DMARC Works?

      TDMARC is an analytical tool that complements the Simple Mail Transfer Protocol (SMTP) by monitoring all three of the standard email authentication protocols namely SPF, DKIM and DMARC. It offers a number of features to secure your email domains ...
    • What Are The Different DMARC Records?

      A DMARC record is where DMARC rule sets are defined. It is a security protocol that will prevent fraudulent entities from misusing your domain to send emails. This record informs the recipients mail server whether a domain is set up to use DMARC. ...
    • DMARC Policy explanation and what policies should I opt for?

      DMARC provides three policy modes, each controlling how receiving mail servers should handle emails that fail DMARC authentication. The outcome of DMARC evaluation depends on the results and alignment of SPF and/or DKIM. Below is an explanation of ...