Site AI Auditod Internet Solutions

DMARC Alignment Explained: Relaxed vs Strict Mode

8. září 2026Čtení: 8 minDoručitelnost e-mailů
DMARC Alignment Explained: Relaxed vs Strict Mode

Short answer: DMARC alignment is the rule that a passing SPF or DKIM check must belong to the same domain as the visible From address. In relaxed mode (the default), the domains only need to share the same organisational domain, so mail.yourdomain.com aligns with yourdomain.com. In strict mode, set with adkim=s or aspf=s, the domains must be identical. Relaxed alignment is the right choice for almost every business; strict mode adds little protection and breaks common subdomain setups.

Why alignment exists

SPF and DKIM were designed before DMARC, and neither looks at the From header that people see. SPF checks the envelope sender domain, which is often a bounce address on a platform’s domain. DKIM checks whatever domain signed the message, which can be any domain the sender controls. A criminal can therefore produce a message that passes SPF and DKIM for their own domain while showing your domain in the From line.

Alignment closes that loophole. DMARC counts an SPF or DKIM pass only if the domain it authenticated matches the From domain. The criminal’s passes for their own domain do not align with yours, so the message fails DMARC, and your policy decides what happens to it.

The question relaxed and strict modes answer is simply how exact that match has to be. The answer affects how you can organise your sending: whether subdomains can authenticate mail for the main domain, and whether the main domain’s signature can cover mail sent from a subdomain address.

What “organisational domain” means

Relaxed alignment compares organisational domains. The organisational domain is the registered domain: the part you buy from a registrar, such as yourdomain.com or yourdomain.co.uk. Everything to the left of it is a subdomain you control.

Receivers determine the organisational domain using the Public Suffix List, a community-maintained list of suffixes such as com, co.uk and many others. That is why relaxed alignment works correctly for country-code domains with second-level suffixes.

Relaxed vs strict at a glance

From domainAuthenticated domainRelaxedStrict
yourdomain.comyourdomain.comAlignedAligned
yourdomain.commail.yourdomain.comAlignedNot aligned
news.yourdomain.comyourdomain.comAlignedNot aligned
news.yourdomain.comnews.yourdomain.comAlignedAligned
yourdomain.comvendor.exampleNot alignedNot aligned

Notice that relaxed alignment works in both directions: a subdomain’s authentication covers the main domain, and the main domain’s authentication covers a subdomain address. Strict mode accepts only the rows where both names are identical.

The last row is the one that matters in practice. Most DMARC failures come from platforms that authenticate with their own domain, and no alignment mode helps with that. The fix is custom domain authentication in the platform.

Setting the mode: adkim and aspf

The DMARC record controls alignment separately for DKIM and SPF:

If the tags are absent, both default to relaxed. A record like v=DMARC1; p=reject; rua=mailto:[email protected] therefore uses relaxed alignment for both. You can mix modes, for example strict for DKIM and relaxed for SPF, but there is rarely a good reason to.

Why relaxed is the right default

Modern e-mail setups rely on subdomains for good reasons:

Relaxed alignment still stops the attack DMARC was built for. An attacker cannot authenticate any domain under your organisational domain without control of your DNS or your sending accounts. If they have that control, strict alignment would not stop them either.

How alignment works in common setups

It helps to walk through the sending streams a typical small business has, and see which check provides the aligned pass in each.

The pattern is clear: relaxed mode never causes a failure for a correctly configured stream, while strict mode can turn a well-configured subdomain setup into a failure. Genuine failures come from streams that do not authenticate your domain at all, which is a configuration issue, not an alignment-mode issue.

It is also worth having two aligned passes where possible. If a message is forwarded, SPF breaks; if a gateway modifies it, DKIM breaks. With both aligned, one surviving check is enough for DMARC to pass.

When strict alignment might make sense

Strict mode can be justified in narrow cases:

Even in those cases, many organisations prefer to publish separate DMARC records for delegated subdomains instead of tightening alignment for everyone. That gives each party control over its own policy and reports without changing how the rest of the domain works.

Before switching, collect DMARC reports and check whether any legitimate source passes only through relaxed alignment. If you enable strict mode with an enforcing policy and such a source exists, its mail will be quarantined or rejected.

Diagnosing alignment failures

When DMARC fails while SPF or DKIM pass, compare three domains in the message headers:

  1. The From domain (header.from= in the DMARC result).
  2. The SPF domain (smtp.mailfrom=, the envelope sender).
  3. The DKIM domain (header.d= or the d= tag in the DKIM-Signature).

If the SPF or DKIM domain belongs to a vendor, set up custom domain authentication with that vendor. If it belongs to a subdomain of yours and you use strict mode, either switch to relaxed or change the configuration so the domains are identical. DMARC aggregate reports show the same information in bulk, in the auth_results and policy_evaluated sections.

Alignment and subdomain policies

Alignment is sometimes confused with the subdomain policy tag sp=. They are different things. sp= sets the policy for mail whose From address is a subdomain, such as billing.yourdomain.com. Alignment decides whether authentication for one name counts for another. A domain can use relaxed alignment and still enforce sp=reject for subdomains that do not send mail, which is a sensible combination for most organisations.

Site AI Audit checks whether your domain publishes DMARC, which policy it uses and whether SPF, DKIM and MX records are in order, and explains each finding in plain words. A free check is a quick way to see the published side before you dig into alignment in headers and reports; paid plans monitor it over time.

Related reading

The bottom line

Alignment is what makes DMARC protect the address people see. Relaxed mode requires the same organisational domain and supports normal subdomain setups; strict mode requires identical domains and is useful only in special cases. Keep the default relaxed alignment, and fix real failures by making every platform authenticate with your domain.

FAQ

What is DMARC alignment?

It is the requirement that the domain authenticated by SPF or DKIM matches the domain in the visible From address. Without alignment, a pass does not count for DMARC.

Is relaxed or strict alignment more secure?

Strict is narrower, but relaxed already prevents outside attackers from passing DMARC, because they cannot authenticate your subdomains. For most domains, strict adds little and breaks legitimate setups.

What is the default DMARC alignment mode?

Relaxed, for both DKIM and SPF. If adkim and aspf are not in your record, relaxed alignment applies.

Does a subdomain signature align with my main domain?

In relaxed mode, yes: a DKIM signature from mail.yourdomain.com aligns with a From address on yourdomain.com. In strict mode it does not.

Why does DMARC fail even though DKIM passes?

Usually because the DKIM signature belongs to the sending platform’s domain rather than yours. Set up custom domain DKIM in that platform.

Can I use strict alignment for DKIM only?

Yes, adkim and aspf are independent. Check DMARC reports first to make sure no legitimate source depends on relaxed DKIM alignment.

#DKIM#DMARC#Email Authentication#SPF
Zkontrolujte svůj web — zdarma.Co na webu opravit — a čím začít.
Začít zdarma

Další z blogu

Všechny články →
Internet Solutions

Další od našeho týmu

Vytvořilo Internet Solutions. Vyzkoušejte i naše další produkty — každý vám ušetří čas jiným způsobem.

internet-solutions.net ↗
Site AI Audit
Přehled soukromí

Tento web používá cookies, abychom vám mohli poskytnout co nejlepší uživatelský zážitek. Informace z cookies se ukládají ve vašem prohlížeči a slouží například k tomu, aby vás web při návratu poznal a náš tým viděl, které části webu jsou pro vás nejzajímavější a nejužitečnější.