Web Technician Online

DMARC failure: check authentication and alignment

Inspect the receiving server’s Authentication-Results in a real message and note the visible From domain, SPF envelope domain and DKIM d= domain.

What does this mean?

DMARC compares the visible From domain with domains authenticated through SPF or DKIM. A message can pass SPF for one domain and still fail DMARC alignment with another. A DNS policy tells receivers what handling is requested; it does not guarantee that every receiver follows that request identically.

What should I check first?

Inspect the receiving server’s Authentication-Results in a real message and note the visible From domain, SPF envelope domain and DKIM d= domain. Keep the timestamp and sending service. Do not diagnose alignment from only a marketing dashboard’s green DNS indicators.

How can I diagnose the cause?

Query the _dmarc policy for the exact domain and review the provider’s signing and return-path settings. The checker retrieves the published policy but does not perform organizational-domain discovery or validate a message. Subdomain policy inheritance can require an additional check with your email provider.

How do I fix it safely?

Configure the legitimate sender to use an appropriate authenticated, aligned domain through its supported process. Preserve the current policy before editing. Do not jump directly to reject until legitimate sources and reporting arrangements have been checked, and do not weaken an established policy permanently to hide one misconfigured service.

Verify the fix and know when to contact your provider

Test mail from each source and review reports where available. Ask the provider for help when custom signing or return-path alignment is unavailable, or when forwarding changes the authentication path. Share redacted headers and expected From domain. Never publish report destinations containing private addresses without a deliberate decision.

Work through these checks in order

  1. Record the visible From domain alongside the receiver’s SPF envelope domain and DKIM signing domain. Identify which authenticated domain, if any, aligns with From under the relevant policy.
  2. Check the published _dmarc policy and the sender’s supported custom signing or return-path settings. For a subdomain, ask about policy inheritance if no exact-name policy is returned.
  3. Repair the specific source and test a new message before strengthening policy. Preserve reporting and inventory legitimate senders so one well-aligned mailbox does not hide a broken website or newsletter source.

Which tool can help?

DMARC DNS record checker · SPF DNS record checker · DKIM public record checker

DNS tools show one resolver’s public answers. Record explainers do not authenticate a message, and calculators do not monitor a server. Use the evidence alongside your provider’s logs.

Reference

Official technical documentation