technical · sourced answer

DMARC Alignment Relaxed vs Strict

DMARC alignment determines if the domain in the From header matches the domain validated by SPF and DKIM. Relaxed alignment allows subdomains to match the organizational domain, while strict alignment requires an exact domain match.

Defining DMARC Alignment

Alignment is the process of verifying that the domain used in the visible From header of an email matches the domain authenticated via SPF or DKIM. Without alignment, a sender could authenticate a message using a random domain they control while spoofing a different brand in the From header. DMARC prevents this by requiring a logical link between the identity and the authentication mechanism.

Mechanical Operation of Relaxed Alignment

In relaxed mode, which is the default setting, DMARC accepts a match if the From header domain and the SPF or DKIM domain share the same organizational domain. For example, if the From header is mail.example.com and the SPF domain is example.com, relaxed alignment considers this a pass because they share the same root domain.

Mechanical Operation of Strict Alignment

Strict alignment requires an exact character for character match between the From header domain and the authenticated domain. Using the previous example, if the From header is mail.example.com and the SPF domain is example.com, strict alignment would fail. Both must be exactly example.com or both must be exactly mail.example.com to pass.

Operational Impact for Senders

Strict alignment provides higher security by preventing any subdomain spoofing but increases the risk of legitimate mail failing DMARC if third party senders use different subdomains. Relaxed alignment is generally preferred for organizations using multiple SaaS tools that send on their behalf. You can verify your current configuration using SendHQ free tools (https://sendhq.cc/tools) to avoid accidental blocks.

Concrete Example Comparison

Scenario: From header is notifications.brand.com. SPF domain is brand.com. Under relaxed alignment (aspf=r), this is a pass. Under strict alignment (aspf=s), this is a fail. Similarly, for DKIM, if the d= tag in the signature is brand.com, relaxed alignment (adkim=r) passes for notifications.brand.com, but strict alignment (adkim=s) fails.

Questions teams ask

Which alignment mode is the default?

Relaxed alignment is the default for both SPF and DKIM if the aspf and adkim tags are omitted from the DMARC record.

When should I use strict alignment?

Use strict alignment when you have total control over all sending infrastructure and want to prevent any unauthorized use of subdomains.

Does changing alignment affect SPF or DKIM records?

No, alignment is a DMARC policy setting. It changes how the receiver evaluates the existing SPF and DKIM results against the From header.

Can I have different modes for SPF and DKIM?

Yes, you can set aspf=s for strict SPF alignment and adkim=r for relaxed DKIM alignment within a single DMARC record.

Primary sources