Why a valid DKIM signature can still fail
DMARC only counts a DKIM pass when the signing domain in d= matches the From domain. Vendors that sign with their own domain pass DKIM and fail DMARC.
A message can carry a perfectly valid DKIM signature and still fail DMARC. The check that decides it is alignment: the domain in the signature's d= tag must match the domain in the visible From header.
Strict and relaxed
- Relaxed, the default, requires only that the organisational domains match. A signature from mail.example.com aligns with a From address at example.com.
- Strict, set with adkim=s in your DMARC record, requires the domains to be identical, subdomain included.
Aligned and not aligned, relaxed mode
From: news@example.com d=mail.example.com -> aligned
From: news@example.com d=example.com -> aligned
From: news@example.com d=vendor.example.net -> NOT alignedThe vendor problem
Out of the box, many marketing and helpdesk platforms sign with their own domain. DKIM passes, the mail looks fine, and DMARC counts a failure because d= is the vendor's domain rather than yours. The fix is always the same: complete the vendor's custom or branded DKIM setup, which publishes a key under your domain and makes them sign with d= set to it.
Aggregate reports make this obvious. Look for sources where dkim=pass but the DMARC result is fail. That combination means unaligned signing, nearly every time.
Check which domain a service actually signs with by sending yourself a message through it and reading the d= tag in the DKIM-Signature header, or by pasting the headers into the header analyzer.
More on DKIM
What DKIM actually does
DKIM signs the message itself, so the proof travels with the mail. That is why it survives forwarding when SPF does not.
Selectors: how one domain holds many DKIM keys
The selector is the label that lets each sending service have its own key under the same domain, and it is what makes rotation possible without downtime.
Publishing your first DKIM key
Generate a 2048-bit key, publish the public half as a TXT record, enable signing, and verify with a real message before you trust it.