← All articlesDeliverability

DMARC alignment: how to check your marketing email

4 min read

DMARC alignment connects successful email authentication to the domain customers see in the From address. A message can pass SPF or DKIM using a different domain and still fail that alignment test. Before changing a policy for your store, identify every legitimate sender, inspect actual messages, and use reporting to understand what stricter enforcement would affect.

Separate passing authentication from alignment

A message can pass SPF or DKIM for a domain without that domain aligning with the visible sender. Alignment is the relationship DMARC checks. The details depend on the configured mode and domains, so inspect the actual message instead of judging by a green label alone.

Use Sendvio's domain setup and alignment guidance for the account, then involve the person who owns DNS. Staff mail, support replies, and other legitimate services may need attention before a stricter policy is appropriate across the domain.

Use a simple alignment test

Imagine a campaign whose visible From address uses the store's domain. The message passes DKIM, but the passing signature belongs to an unrelated domain. That result authenticates something, yet it does not establish the aligned identity the store needs. By contrast, a passing signature using an appropriately aligned domain can satisfy DMARC even when another authentication path does not.

Strict alignment requires an exact domain match. Relaxed alignment allows the applicable organizational-domain relationship rather than requiring identical names. The correct interpretation depends on the actual domains, published policy, and receiver evaluation. Have the administrator inspect those values instead of treating all subdomains or visually similar domains as automatically equivalent.

This is also why changing the Reply-To address does not solve a DMARC failure. Replies and authentication serve different purposes. Keep the customer's reply path useful, but diagnose alignment from the identities in the delivered message.

Review before enforcing

A monitoring policy can help reveal which systems send mail using your domain. Reports require interpretation: unfamiliar traffic may be unauthorized, but it may also belong to a legitimate service someone forgot to document.

Do not copy a strict policy from a tutorial and assume it is safe. Tightening enforcement before legitimate senders are ready can disrupt expected messages. Keep a change record and an agreed response plan if problems appear after the update.

Treat policy and reporting as operational decisions

A policy of none does not request special handling for failed validation. Quarantine communicates that failures should be treated as suspicious; reject expresses a stronger handling preference. Receiving systems still make their own disposition decisions using additional information. None of these settings guarantees that wanted mail lands in the inbox or that every impersonation attempt disappears.

Aggregate reports can help show which systems send using the domain and how authentication and alignment were evaluated. They are operational evidence, not a campaign-engagement report. Assign someone to interpret them and investigate unknown senders. An unfamiliar source may be an overlooked legitimate service, a forwarding effect, or unauthorized use; those possibilities require different action.

Check the outcome regularly

Send controlled tests and inspect alignment, then review reports with a qualified administrator. Domain protection is an ongoing configuration responsibility, particularly when adding a new sending service or changing a brand domain.

Keep expectations realistic. DMARC helps protect sender identity and addresses authentication failures. It does not prevent every phishing attempt or guarantee inbox placement for your campaigns. Combine it with recognizable sender information, appropriate permissions, and a steady pattern of messages people expect to receive.

Build a sender inventory before tightening policy, including staff, support, marketing, and operational services. Test each relevant path and keep a record of its expected aligned identity. If an update disrupts legitimate traffic, that inventory helps identify the affected service without weakening the entire domain configuration blindly.

Use current standards and account-specific instructions when planning changes. DMARC specifications and implementations evolve, so an old tutorial's rollout parameters may no longer be the right basis for a new setup. The merchant's practical objective remains clear: know who legitimately uses the domain, verify their alignment, and choose a policy with an understood impact on real mail. Revisit that evidence whenever the sending architecture changes.

Put it into practice

Explore domain alignment