---
title: Authenticated Received Chain (ARC) Explained | SendHQ
description: Learn how Authenticated Received Chain (ARC) preserves email authentication results during forwarding to prevent DMARC failures.
canonical: https://sendhq.cc/terms/arc
last-updated: 2026-08-26
---
# Authenticated Received Chain (ARC) Explained

Authenticated Received Chain (ARC) is an email authentication standard that allows intermediate mail servers to sign the results of SPF, DKIM, and DMARC checks. This ensures that when an email is forwarded, the final receiving server can trust the original authentication status even if the forwarding process broke the original SPF or DKIM signatures.

## How ARC Works Mechanically

ARC operates by adding three specific headers to an email as it passes through an intermediate server. The ARC-Seal- authentication provides a digital signature over the ARC-Message-Seal, which contains the ARC-Authentication-Results. This chain creates a verifiable record of the authentication status at each hop. If a message is forwarded, the next server can verify the ARC chain to see that the message was legitimate before the forwarder modified the envelope or headers.

## Importance for Email Senders

ARC is critical for senders whose emails are frequently forwarded by users or mailing lists. Without ARC, a forwarder often changes the sender address or modifies the message body, causing SPF and DKIM to fail. If the sender has a strict DMARC reject policy, these legitimate forwarded emails would be blocked. ARC provides a mechanism for the final receiver to ignore a DMARC failure if a trusted intermediate server has already validated the message.

## Operational Notes and Common Mistakes

A common mistake is assuming ARC replaces DKIM or SPF. ARC is a supplementary layer that depends on those protocols. It only works if the intermediate server supports ARC and the final receiving server trusts the ARC sealer. Senders should still use SendHQ free tools (https://sendhq.cc/tools) to ensure their primary DKIM and SPF records are correctly configured before relying on ARC for forwarding scenarios.

## Concrete Implementation Example

Consider a user forwarding work email to a personal Gmail account. The work server signs the mail with DKIM. The forwarding server receives it, validates DKIM, and adds an ARC seal. When Gmail receives the mail, the original SPF fails because the forwarding server is not an authorized sender. However, Gmail sees the ARC seal from the trusted forwarder, verifies the original DKIM result stored in the ARC header, and delivers the mail instead of rejecting it.

## ARC and DMARC Interaction

ARC acts as a safety net for DMARC. While DMARC evaluates the current state of the message, ARC provides a historical record of authentication. If the current DMARC check fails but a valid ARC chain exists from a trusted source, the receiving mail transfer agent can choose to override the DMARC policy and accept the message, reducing false positives in spam filters.

## Questions teams ask

**Does ARC replace DMARC?**

No, ARC does not replace DMARC. It provides a way to preserve authentication results so that DMARC can be evaluated more accurately after a message has been forwarded.

**Who needs to implement ARC?**

ARC is primarily implemented by mail intermediaries, such as mailing list managers, forwarding services, and enterprise email gateways.

**Will ARC stop all spam?**

No, ARC is designed to prevent legitimate forwarded mail from being marked as spam, not to stop spam itself. It relies on the trust between the sealer and the receiver.

**Is ARC supported by all email providers?**

Most major providers like Gmail and Microsoft 365 support ARC, but adoption varies across smaller mail servers and legacy systems.

## Primary sources

- [RFC 8617: The Authenticated Received Chain (ARC)](https://www.rfc-editor.org/rfc/rfc8617) — RFC Editor
- [RFC 7489: Domain-based Message Authentication, Reporting and Conformance](https://www.rfc-editor.org/rfc/rfc7489) — RFC Editor
- [RFC 6376: DomainKeys Identified Mail](https://www.rfc-editor.org/rfc/rfc6376) — RFC Editor

## Continue learning

[email dkim spf dmarc](https://sendhq.cc/guides/email-dkim-spf-dmarc.md) [dmarc check](https://sendhq.cc/guides/dmarc-check.md) [email deliverability](https://sendhq.cc/guides/email-deliverability.md) [email domain verification](https://sendhq.cc/guides/email-domain-verification.md)
