All tips
DKIM 2 min read

Why a valid DKIM signature can still fail

DMARC only counts a DKIM pass when the signing domain in d= matches the From domain. Vendors that sign with their own domain pass DKIM and fail DMARC.

A message can carry a perfectly valid DKIM signature and still fail DMARC. The check that decides it is alignment: the domain in the signature's d= tag must match the domain in the visible From header.

Strict and relaxed

  • Relaxed, the default, requires only that the organisational domains match. A signature from mail.example.com aligns with a From address at example.com.
  • Strict, set with adkim=s in your DMARC record, requires the domains to be identical, subdomain included.

Aligned and not aligned, relaxed mode

From: news@example.com     d=mail.example.com   -> aligned
From: news@example.com     d=example.com        -> aligned
From: news@example.com     d=vendor.example.net -> NOT aligned

The vendor problem

Out of the box, many marketing and helpdesk platforms sign with their own domain. DKIM passes, the mail looks fine, and DMARC counts a failure because d= is the vendor's domain rather than yours. The fix is always the same: complete the vendor's custom or branded DKIM setup, which publishes a key under your domain and makes them sign with d= set to it.

Aggregate reports make this obvious. Look for sources where dkim=pass but the DMARC result is fail. That combination means unaligned signing, nearly every time.

Check which domain a service actually signs with by sending yourself a message through it and reading the d= tag in the DKIM-Signature header, or by pasting the headers into the header analyzer.

Look up a DKIM selector and key strength
dkimdmarcalignment