A DMARC failure means neither SPF nor DKIM produced a passing result with an identity aligned to the visible From domain. Both mechanisms can pass individually and DMARC still fail, which is the single most confusing outcome in email authentication and the most common one.
Most common causes
- SPF passes on a third-party envelope domain but is not aligned
- DKIM signs with a provider domain rather than the visible From domain
- The relevant authentication mechanism failed
- Strict alignment is enabled without exact-domain identities
What to verify next
- Run DMARC Alignment Lab
- Inspect Authentication-Results in the message header
- Verify custom bounce and DKIM domains
- Inventory every legitimate sending platform
Authentication and alignment are different tests
SPF authenticates the envelope sender domain; DKIM authenticates the signing domain. DMARC then asks whether either of those authenticated domains matches the From domain. A platform that passes SPF for its own bounce domain and DKIM for its own signing domain has passed both tests and aligned neither.
Read Authentication-Results in a delivered message. It lists the SPF identity (smtp.mailfrom), the DKIM identity (header.d) and the DMARC verdict with the From domain. The mismatch is visible in one line.
The standard fixes
Configure the sending platform with a custom bounce domain under your domain so SPF aligns, and with custom DKIM signing so header.d is your domain. Most platforms support at least one; configuring both gives redundancy when forwarding breaks the SPF path.
Forwarded mail and mailing lists fail SPF alignment inevitably and can invalidate DKIM if they modify content. A DKIM signature that survives forwarding is the durable path, which is why DKIM alignment matters more than SPF alignment for reliability.
- Custom bounce domain: SPF alignment.
- Custom DKIM signing: DKIM alignment.
- DKIM survives forwarding; SPF does not.
Verify with the actual sending path
Dashboards describe intent; headers describe reality. After configuring alignment, send through the same platform to a mailbox you control and confirm dmarc=pass. Use DMARC Alignment Lab to model the identities before and after the change.
Keep aggregate reporting enabled. It is the only routine feedback that shows which sources are still failing alignment across all receivers.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisDMARC Alignment Lab
Compare visible From, envelope sender and DKIM identities without reducing the result to a pass/fail label.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Relaxed versus strict alignment changes what counts as a match; check the domain’s adkim and aspf tags.
- Receivers may override DMARC with local policy, so a fail does not always mean rejection.
Common questions
SPF says pass. Why does DMARC fail?
SPF passed for the envelope domain, which belongs to the platform. It is not your From domain, so it does not align.
Which is easier to fix, SPF or DKIM alignment?
DKIM, usually: one selector record. It is also the path that survives forwarding.
Will p=none stop the failures?
No. p=none stops receivers from acting on failures; the failures continue and are reported. Fix alignment.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.