DIAGNOSTIC PLAYBOOK
Forwarded mail and DMARC: investigate receiver overrides
Forwarding can break SPF and sometimes DKIM, leaving receivers to apply additional local evidence. A local override or ARC result can help explain acceptance without changing the original DMARC authentication result.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Compare a direct message with the forwarded version and identify where authentication stops passing.
- Inspect ARC and reported override reasons from trusted receiving infrastructure.
- Work with the forwarder on signature preservation and supported handling rather than authorizing every relay in your SPF.
What this looks like
ILLUSTRATIVE EXAMPLE
A mailing intermediary changes a message and the final receiver accepts it based on its own trust assessment. That acceptance is not a new aligned signature from the original domain.
A mistake to avoid
ARC presence is not a universal bypass. The receiver decides whether to trust the intermediary and how to handle the message.
Keep the result in context
DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.