On this page
  1. What dmarc=fail means
  2. How to read the Authentication-Results header
  3. Why DMARC fails
  4. A service sends with its own domain
  5. Forwarding and mailing lists
  6. A server missing from SPF, or a changed message
  7. Strict alignment
  8. How to fix it
  9. 1. Find the sender that fails
  10. 2. Sign DKIM with your domain
  11. 3. Or align the MAIL FROM, and publish SPF on it
  12. 4. Use a dedicated subdomain if the service supports it
  13. 5. Keep relaxed alignment
  14. What happens to mail that fails
  15. Check your records
  16. Sources

dmarc=fail means a DMARC policy applies to the domain in the message's From address, but neither Sender Policy Framework (SPF) (opens in a new tab) nor DomainKeys Identified Mail (DKIM) (opens in a new tab) passed for a domain aligned with it (RFC 9989 section 5.3 (opens in a new tab)). One aligned pass from either is enough. To fix it, have the service that failed sign DKIM with your domain, or send with a MAIL FROM domain aligned with yours (Microsoft (opens in a new tab)).

What dmarc=fail means

RFC 9989 (opens in a new tab), which obsoletes RFC 7489, defines DMARC (Domain-based Message Authentication, Reporting, and Conformance). DMARC checks the domain in the message's From address, using two other checks:

DMARC does not use their pass or fail alone. It uses the domain each one authenticated: the d= domain of a valid DKIM signature, and the MAIL FROM domain that SPF validated (RFC 9989 section 4.4 (opens in a new tab)). A message passes when at least one of those domains is aligned with the From domain, and fails when none is (section 5.3 (opens in a new tab)).

Aligned does not have to mean identical. With relaxed alignment, the default, the two domains share the same Organizational Domain, in practice the root domain, so a subdomain aligns with it; with strict alignment they must be identical (section 3.2.10 (opens in a new tab), Microsoft (opens in a new tab)).

This is how SPF and DKIM can each show pass while DMARC shows fail. Any domain owner can publish an SPF record for its own domain and get an SPF pass, and a message can carry a valid DKIM signature from any domain, which is why DMARC requires alignment.

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.

How to read the Authentication-Results header

Message headers carry the results of the SPF, DKIM and DMARC checks (Google Workspace (opens in a new tab)). For a message sent from your domain, you can paste its headers into Google Admin Toolbox's Messageheader tool. In Microsoft 365, open the message headers and find the Authentication-Results header that Microsoft 365 added (Microsoft (opens in a new tab)).

Microsoft's example is a message where SPF and DKIM both pass, but DMARC fails because neither domain aligns with the From domain. Here it is with the domain names replaced by example ones:

Authentication-Results: spf=pass (sender IP is 198.51.100.10)
 smtp.mailfrom=bounces.example.net; dkim=pass (signature was verified)
 header.d=example.net; dmarc=fail action=oreject
 header.from=example.com;compauth=fail reason=000

Three fields show which domain each check used:

Field What it holds
smtp.mailfrom= The MAIL FROM domain that SPF checked, for SPF alignment
header.d= The DKIM signing domain, for DKIM alignment
header.from= The From domain; DMARC passes if either the SPF or the DKIM domain aligns with it

In the example, bounces.example.net and example.net are in a different organizational domain from example.com, so both alignment checks fail and DMARC fails.

In Microsoft 365, the action= value after dmarc=fail shows the policy the sender published and what Microsoft 365 did:

  • action=none: the sender published p=none, and no DMARC-specific action was taken; other filtering still applies.
  • action=quarantine: the sender published p=quarantine, and the message was quarantined or junked.
  • action=oreject: the sender published p=reject, and the message was rejected.

Why DMARC fails

A service sends with its own domain

Mail that authorized third parties send for you might not be aligned, which also prevents a pass (RFC 9989 section 7.3 (opens in a new tab)). Microsoft (opens in a new tab) gives the symptom: SPF passes for the service's domain but DMARC fails, because the MAIL FROM uses the service's domain and the service does not sign DKIM with yours. In a related case DKIM passes but DMARC still fails, because the DKIM d= value is the service's domain and doesn't align with your From domain.

Forwarding and mailing lists

Forwarding often breaks SPF: at the final mailbox, the forwarding server's address is not one the original MAIL FROM domain authorized (RFC 9989 section 7.4 (opens in a new tab)). If the forwarder rewrites the MAIL FROM to its own domain, SPF might pass, but that domain does not align with the original From domain (RFC 7960 (opens in a new tab)). DMARC then depends on DKIM.

An aligned DKIM signature can survive forwarding when the signed headers and body stay unchanged: an alias that preserves the content and makes no significant header changes may leave DKIM signatures valid, while modifying the content invalidates most DKIM signatures. Microsoft (opens in a new tab) names mailing lists and transport rules that change the body after signing as a cause of DKIM failure. When neither SPF nor DKIM passes in alignment, DMARC fails.

Mail sent through mailing lists with an unmodified From line is frequently rejected under a p=reject policy, and mailing list software has adopted workarounds to make the From line DMARC aligned. Yahoo (opens in a new tab) asks senders who forward email to implement ARC (Authenticated Received Chain), and Microsoft suggests trusted ARC sealers at the destination.

A server missing from SPF, or a changed message

Google's troubleshooting guide (opens in a new tab) lists two more causes: the message was sent by a server that isn't in your SPF record, or it was modified in transit or after the DKIM signature was added. Check that your SPF record includes every IP address and domain allowed to send mail for your domain.

Strict alignment

With aspf=s in your DMARC record, SPF alignment needs an exact match, so it fails when the MAIL FROM domain is a subdomain of the From domain, such as bounces.example.com for example.com. DMARC can still pass through aligned DKIM, because one aligned check is enough. Microsoft's fix is to change to aspf=r (relaxed) or make the From address match the subdomain. Google notes that strict alignment increases the likelihood that messages are rejected or sent to spam, and nearly all domain owners have found relaxed alignment sufficient (RFC 9989 section 4.4 (opens in a new tab)).

How to fix it

1. Find the sender that fails

For a single message, compare smtp.mailfrom= and header.d= with header.from= in its header. For a wider view, DMARC aggregate reports can reveal mail streams that use your domain but don't pass DMARC (RFC 9989 section 5.1.6 (opens in a new tab)). They come only from receivers that send them; some opt out (section 5.3 (opens in a new tab)).

2. Sign DKIM with your domain

For DKIM to count, your mail must carry a DKIM signing domain aligned with your From domain (RFC 9989 section 5.1.2 (opens in a new tab)). For a third-party service, that means configuring custom DKIM signing at the service using your domain (Microsoft (opens in a new tab)). Domains that publish p=reject must not rely on SPF alone and must apply valid DKIM signatures (section 7.4 (opens in a new tab)).

3. Or align the MAIL FROM, and publish SPF on it

For SPF to count, your mail must use a MAIL FROM domain aligned with your From domain (RFC 9989 section 5.1.1 (opens in a new tab)). Set the service's envelope sender to your domain, as Google (opens in a new tab) asks, or to a subdomain of it, which Microsoft also allows; then publish the service's SPF record on that exact MAIL FROM domain. Receivers look up SPF at the domain of the MAIL FROM address (RFC 7208 section 4 (opens in a new tab)), and each subdomain used for email needs its own SPF record, so a record on example.com does not cover bounces.example.com. The SPF record generator builds a record from the services that send email for your domain.

4. Use a dedicated subdomain if the service supports it

If the service can sign DKIM with a subdomain of yours, send from an address on that subdomain, publish a separate DMARC record for the subdomain, and have the service sign DKIM with the same subdomain.

5. Keep relaxed alignment

Relaxed alignment, the default, accepts a subdomain of your domain, for example mail.example.com for example.com; strict requires an exact match, and most domains keep relaxed (DMARC record generator).

What happens to mail that fails

Each receiver decides. The final handling of any message is left to the receiver's own policies, and a receiver may accept mail that fails DMARC even when the policy is p=reject (RFC 9989 section 5.4 (opens in a new tab)).

For inbound mail with Honor DMARC record policy on, Microsoft 365 (opens in a new tab) takes no DMARC-specific action at p=none, though other filtering still applies. It sends p=quarantine failures to the Junk Email folder (configurable to quarantine) and rejects p=reject failures during SMTP with 550 5.7.1.

Gmail may mark unauthenticated messages as spam or reject them with a 5.7.26 error (Google's sender guidelines (opens in a new tab)). When a message from your domain fails DMARC, the sender might get this in the bounce (Google Workspace (opens in a new tab)): "Unauthenticated email from domain-name is not accepted due to domain's DMARC policy." If your policy is p=none and messages still go to spam, the cause might be something other than your DMARC record.

Don't tighten the policy while legitimate mail still fails: legitimate streams that fail alignment must be fixed before any move to enforcement (RFC 9989 section 5.1.6 (opens in a new tab)). The DMARC policy not enabled guide covers the order for moving from p=none to quarantine or reject.

Check your records

After you change a sender's setup, DemiSignal's check reads the public DNS records of the domain you enter and checks your SPF, DKIM and DMARC records, with no account needed. A DNS finding shows how your domain is set up; it does not show where a particular message landed. To confirm the fix for one sender, send a new test message through it and read its header.

Sources

Tools for this

Frequently asked questions

What does dmarc=fail mean?

A DMARC policy applies to the domain in the From address, but neither SPF nor DKIM passed for a domain aligned with it. One aligned pass from either is enough for DMARC to pass.

Why does DMARC fail when SPF and DKIM both pass?

The domains that passed are not aligned with the From domain, for example when a service uses its own domain for the MAIL FROM and signs DKIM with its own domain.

Does forwarding make DMARC fail?

Forwarding often breaks SPF. Rewriting the MAIL FROM may restore SPF without aligning it with the original From domain. DMARC can still pass if an aligned DKIM signature survives; changes to signed headers or the body can break that signature.

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.