generic error

DMARC Fail — Authentication Did Not Align

Neither the SPF-authenticated identity nor the DKIM-authenticated identity supplied a passing path aligned with the visible From domain.

A DMARC failure means neither SPF nor DKIM produced a passing result with an identity aligned to the visible From domain. Both mechanisms can pass individually and DMARC still fail, which is the single most confusing outcome in email authentication and the most common one.

Reviewed 2026-09-02. Provider wording and requirements change; the provider reference below is authoritative.

Most common causes

  • SPF passes on a third-party envelope domain but is not aligned
  • DKIM signs with a provider domain rather than the visible From domain
  • The relevant authentication mechanism failed
  • Strict alignment is enabled without exact-domain identities

What to verify next

  1. Run DMARC Alignment Lab
  2. Inspect Authentication-Results in the message header
  3. Verify custom bounce and DKIM domains
  4. Inventory every legitimate sending platform

Authentication and alignment are different tests

SPF authenticates the envelope sender domain; DKIM authenticates the signing domain. DMARC then asks whether either of those authenticated domains matches the From domain. A platform that passes SPF for its own bounce domain and DKIM for its own signing domain has passed both tests and aligned neither.

Read Authentication-Results in a delivered message. It lists the SPF identity (smtp.mailfrom), the DKIM identity (header.d) and the DMARC verdict with the From domain. The mismatch is visible in one line.

The standard fixes

Configure the sending platform with a custom bounce domain under your domain so SPF aligns, and with custom DKIM signing so header.d is your domain. Most platforms support at least one; configuring both gives redundancy when forwarding breaks the SPF path.

Forwarded mail and mailing lists fail SPF alignment inevitably and can invalidate DKIM if they modify content. A DKIM signature that survives forwarding is the durable path, which is why DKIM alignment matters more than SPF alignment for reliability.

  • Custom bounce domain: SPF alignment.
  • Custom DKIM signing: DKIM alignment.
  • DKIM survives forwarding; SPF does not.

Verify with the actual sending path

Dashboards describe intent; headers describe reality. After configuring alignment, send through the same platform to a mailbox you control and confirm dmarc=pass. Use DMARC Alignment Lab to model the identities before and after the change.

Keep aggregate reporting enabled. It is the only routine feedback that shows which sources are still failing alignment across all receivers.

Best diagnostic path

Known limits

  • Relaxed versus strict alignment changes what counts as a match; check the domain’s adkim and aspf tags.
  • Receivers may override DMARC with local policy, so a fail does not always mean rejection.

Common questions

SPF says pass. Why does DMARC fail?

SPF passed for the envelope domain, which belongs to the platform. It is not your From domain, so it does not align.

Which is easier to fix, SPF or DKIM alignment?

DKIM, usually: one selector record. It is also the path that survives forwarding.

Will p=none stop the failures?

No. p=none stops receivers from acting on failures; the failures continue and are reported. Fix alignment.

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.