Dev.to
7/14/2026

The original headline is: "Your email passes SPF and DKIM but still fails DMARC. Here's why"
Original: Your email passes SPF and DKIM but still fails DMARC. Here's why
Short summary
DMARC requires not just that SPF or DKIM pass, but that the authenticated domain aligns with the visible From header domain. The article explains alignment modes (relaxed vs strict) and covers four common failure scenarios: provider sending with non-aligned domains, forwarding breaking SPF and DKIM, broken DKIM leaving only non-aligned SPF, and unintended strict mode settings.
- •DMARC alignment requires authenticated domain to match the From header domain, not just a pass result
- •Relaxed alignment (default) requires matching organizational domain; strict requires exact match
- •Four common failure scenarios: provider non-alignment, forwarding, broken DKIM, and unintended strict mode
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



