Spam & deliverability
Why do forwarded emails sometimes fail authentication?
Short answer: Forwarding changes the server delivering the message and can break SPF; message modifications can also invalidate DKIM.
The full answer
The forwarder’s server may not appear in the original domain’s SPF policy. Sender Rewriting Scheme can help with forwarding behavior, but a rewritten envelope sender does not necessarily provide SPF alignment with the original visible From address.
An unchanged, aligned DKIM signature may allow DMARC to pass even when SPF fails. Mailing lists that rewrite subjects or add footers can invalidate signatures. Some receiving systems consider ARC evidence, but acceptance is receiver-dependent.
Compare the original and forwarded message headers before changing DNS. Do not add an unknown forwarding service to SPF just to silence a warning; authorize only services that should send using your domain.
