Is it necessary for both SPF and DKIM to pass for an email to be authenticated?
Is it necessary for both SPF and DKIM to pass for an email to be authenticated?
Even if any one of them passes, the email is considered to be authenticated. Only if both of them fail, the email would be considered as a spoofed email and the policy would be applicable.