Free browser tool · No signup required
DMARC alignment explainer tool
Compare one authenticated domain with the visible From domain under explicit strict or relaxed alignment assumptions.
Prepare your inputs
Authentication success and domain alignment are different checks. This tool explains one SPF or DKIM path. Supply the domain used by that mechanism, rather than a display name or complete email address.
Runs in this browser. Inputs are not sent by this tool or saved in browser storage. Start with the fictional example; use redacted text for reviews.
How it works
Strict mode compares exact domains. Relaxed mode checks that both names fall within an organizational domain you independently verified. Select whether the mechanism passed to see whether this single path supports DMARC.
Worked example
From example.com and DKIM d=mail.example.com differ in strict mode. Under a verified example.com organizational boundary they align in relaxed mode, but only a passing signature supplies a successful path.
Limits and interpretation
The tool trusts the supplied boundary and performs no DNS discovery or public-suffix lookup. It is not a complete RFC 9989 evaluator. Another signature or SPF path can change the message-level outcome.
Examples are synthetic, not customer results. RFC 9989: DMARC alignment