Why does DMARC fail when SPF or DKIM appears to pass?
DMARC fails when an SPF or DKIM pass is not aligned with the RFC 5322 From domain. Compare the SPF MailFrom domain and each passing DKIM d= domain with the From domain under the published strict or relaxed mode. Even a corrected DMARC pass does not guarantee inbox delivery because final handling remains local policy.
First 15 minutes
- Compare the SPF-authenticated MailFrom domain and each passing DKIM d= domain with the RFC 5322 From domain.
- Read the DMARC record's relaxed or strict alignment modes.
- Confirm that at least one authenticated identifier passes and aligns with the author domain.
Now
- Align at least one passing SPF or DKIM authenticated domain with the RFC 5322 From author domain.
Next 24 hours
- Receive and analyze DMARC aggregate reports to identify authorized sources and remaining authentication gaps.
Next 7 days
- Correct the authorized sources still shown with authentication or alignment gaps in aggregate reports.
Technical checks
IT / DNS
- Compare MailFrom and every passing DKIM d= domain with the RFC 5322 From domain under the selected alignment mode.
- Confirm the DMARC result is pass only when at least one authenticated identifier aligns.
Verification criteria
- Confirm a current message receives DMARC pass because at least one authenticated identifier passes and aligns with the author domain.
- Confirm aggregate reports identify the authorized sources and show whether authentication gaps remain.
Escalation criteria
- Escalate to DNS or deliverability owners when aggregate reports continue to show authorized sources with authentication gaps.
- Escalate remaining placement problems separately when DMARC passes because receiver handling is still local policy.
Prevention
- Keep at least one SPF or DKIM authenticated domain aligned with the RFC 5322 From domain.
- Review DMARC aggregate reports so authorized sources and authentication gaps remain visible.
Business impact
- An unaligned SPF or DKIM pass is insufficient for DMARC, while even a DMARC pass does not guarantee inbox placement.
Open questions
- The failing path cannot be identified without a real received message's Authentication-Results, From, Return-Path and DKIM d= values.
- Receiver disposition after DMARC failure is local policy and can differ even when the protocol result is identical.
- Forwarders and mediators may alter SPF or DKIM outcomes; the actual message path must be inspected before assigning fault.
Sources (6)
- RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance — Introduction, paragraphs 4-5IETF RFC 9989
- RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance — Introduction, paragraph 5; Identifier AlignmentIETF RFC 9989
- RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance — Sections 4.4, 5.3.3 and 5.3.4IETF RFC 9989
- RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance — Section 5.3.5, Determine DMARC Pass or FailIETF RFC 9989
- RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance — Sections 5.1 and 5.1.3-5.1.5IETF RFC 9989
- RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance — Introduction paragraph 6 and Section 5.4IETF RFC 9989


