Email security
Why can SPF and DKIM pass while DMARC fails?
Short answer: DMARC requires a passing SPF or DKIM identity to align with the domain in the visible From address.
The full answer
SPF checks the envelope sender or applicable HELO identity, not necessarily the address a person sees. DKIM validates a signature for its d= signing domain. Those checks can both pass for a service provider’s domain while your own From domain remains unaligned.
For example, a newsletter may authenticate under the provider’s domain while displaying your business address. Configure a provider-supported custom return-path or aligned DKIM signing domain, using the instructions for your account. Do not invent signing keys or DNS values.
Inspect Authentication-Results on a real message. DMARC passes when at least one eligible aligned check passes. Relaxed alignment normally permits domains sharing the same organizational domain; strict alignment requires exact domain matches.
