Email glossary · Practical guide
DMARC alignment: compare authenticated domains with the author domain
Alignment is the relationship between an authenticated domain and the message's From domain. Passing authentication for an unrelated service domain does not establish that relationship.
Reviewed · Examples are illustrative
Who this helps: Readers checking a term before making an outreach or mailbox decision.
Meaning and common confusion
Write the domains beside the results so the comparison is visible. Exact equality and a permitted organizational-domain relationship are different alignment modes. Current DMARC policy discovery and receiver implementation also matter in complicated domain structures; avoid guessing an organizational boundary from string similarity alone.
Worked example
This is a synthetic illustration, not a customer result or a live configuration to copy.
From domain: brand.example
Passing DKIM domain: unrelated.example
Result to investigate: authentication passed for a different identity
Repair question: can the authorized sender sign with an appropriate aligned domain?Checks to make
- Identify which mechanism actually passed.
- Read the configured alignment mode.
- Test the intended sender after a provider-side change.
Next step and limits
Use the relaxed-versus-strict guide for a scoped comparison. Do not weaken a policy merely to hide a wrong sender configuration. Alignment is domain evidence, not proof that the email content is safe, relevant or solicited.
Source: Zintara product context for this operational definition
Source references
Worked examples are illustrative. Editorial procedures are suggested methods, not measured performance claims or promises of additional product features.
Related guides
- DMARC relaxed vs strict alignment: compare the authenticated domains →
- Why DMARC can fail when SPF and DKIM pass →