Definition · DNS & Email Spoofing
What is DMARC Alignment?
DMARC alignment is the rule at the heart of DMARC: for a message to pass, it is not enough for SPF or DKIM to pass in isolation — the domain that passed must also align with the domain in the From header that the recipient actually sees.
Why alignment exists
SPF validates the envelope sender (Return-Path) domain, and DKIM validates whichever domain signed the message. Neither, on its own, says anything about the From header. An attacker could send mail with a From header of ceo@yourcompany.com while using their own domain in the envelope and DKIM signature — and both checks would pass. Alignment closes this loophole by tying authentication to the visible sender.
Relaxed vs strict alignment
DMARC supports two alignment modes, set independently for SPF (aspf) and DKIM (adkim):
- Relaxed (default) — the authenticated domain and the From domain must share the same organisational domain;
mail.example.comaligns withexample.com - Strict — the domains must match exactly;
mail.example.comdoes not align withexample.com
Common alignment failures
Third-party senders are the usual cause: a marketing platform or helpdesk sending “on behalf of” your domain may pass SPF for its own domain but fail alignment for yours. The fix is to configure custom DKIM signing (and, where supported, a custom Return-Path) so the third party authenticates as your domain. Monitoring DMARC aggregate reports reveals which senders are failing alignment before you move to an enforcing policy.