About the DMARC Alignment Checker (adkim / aspf)
DMARC passes only when SPF or DKIM passes and is aligned with the domain in the visible From header. The adkim and aspf tags decide how exact that match has to be. r (relaxed, the default) accepts any domain within the same organisational domain, so mail.example.com aligns with example.com. s (strict) requires the exact same domain name. The checker above shows which alignment modes a domain publishes; when the tags are missing, both are relaxed.
For DKIM, alignment compares the d= domain in the DKIM signature with the From domain. For SPF, it compares the domain of the envelope sender (the Return-Path, or MAIL FROM) with the From domain. That second comparison is where most alignment failures come from: email service providers often use their own bounce domain, such as bounces.provider.net, so SPF passes for the provider but is not aligned with your domain. Setting up a custom return-path subdomain (for example bounce.example.com) fixes that under relaxed alignment, not under strict.
For nearly every domain relaxed alignment is the right choice. Strict alignment adds protection only in narrow cases, such as organisations that delegate subdomains to parties they do not fully trust, and it breaks legitimate setups that sign or bounce from a subdomain.
How to use it
- Enter a domain above and run the DMARC check.
- Look for adkim and aspf in the tag table. Absent means r (relaxed).
- For mail that fails DMARC, compare the From domain with the DKIM d= domain and the Return-Path domain in the message headers.
- If a sending service uses its own bounce domain, configure a custom return-path or rely on DKIM alignment for that service.
- Only switch to s after reports confirm that every legitimate source uses exactly the From domain.
Examples
- From: news@example.com, DKIM d=mail.example.com: aligned with adkim=r, not aligned with adkim=s.
- From: news@example.com, DKIM d=example.com: aligned in both modes.
- From: billing@example.com, Return-Path bounce.example.com, SPF pass: aligned with aspf=r, not with aspf=s.
- From: billing@example.com, Return-Path bounces.sendgrid.net, SPF pass: not aligned in either mode; DMARC can still pass if DKIM is signed as example.com.
- From: info@example.co.uk, DKIM d=example.co.uk: aligned, because the public suffix list treats co.uk as a suffix and example.co.uk as the organisational domain.
Relaxed versus strict at a glance
- adkim=r: DKIM d= may be the From domain or any subdomain of the same organisational domain.
- adkim=s: DKIM d= must be exactly the From domain.
- aspf=r: the Return-Path domain may be the From domain or any subdomain of the same organisational domain.
- aspf=s: the Return-Path domain must be exactly the From domain.
- DMARC passes when at least one of the two is both passing and aligned.
Why DKIM alignment matters more than SPF alignment
SPF breaks when mail is forwarded, because the forwarding server's address is not in your SPF record. A valid DKIM signature survives forwarding as long as the message is not modified. That makes an aligned DKIM signature the most reliable way to pass DMARC. Make sure every service that sends as your domain signs with your domain (or a subdomain of it) rather than its own default d= domain.
When strict alignment makes sense
Strict mode is useful when subdomains are run by other parties and must not be able to send mail that passes DMARC for the main domain, or when a regulator or security baseline requires it. In other cases it mostly creates failures: many platforms sign with a subdomain like em123.example.com, which relaxed mode accepts and strict mode rejects.
Frequently asked questions
What does adkim=r mean?
Relaxed DKIM alignment: the domain in the DKIM signature (d=) only needs to share the organisational domain with the From address, so subdomains count as a match. It is the default.
What does aspf=s mean?
Strict SPF alignment: the domain of the envelope sender (Return-Path) must be identical to the From domain. A bounce subdomain no longer counts.
Which alignment should I use?
Relaxed for both, unless you have a specific reason for strict. Relaxed still blocks spoofing from unrelated domains.
Why does DMARC fail when SPF and DKIM both pass?
Because neither is aligned. SPF passed for the provider's bounce domain and DKIM was signed with the provider's domain, not yours. Configure DKIM signing with your own domain to fix it.
If adkim and aspf are missing, what applies?
Both default to r, relaxed alignment.