DIAGNOSTIC PLAYBOOK

Forwarded mail and DMARC: investigate receiver overrides

Forwarding can break SPF and sometimes DKIM, leaving receivers to apply additional local evidence. A local override or ARC result can help explain acceptance without changing the original DMARC authentication result.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Compare a direct message with the forwarded version and identify where authentication stops passing.
  2. Inspect ARC and reported override reasons from trusted receiving infrastructure.
  3. Work with the forwarder on signature preservation and supported handling rather than authorizing every relay in your SPF.

What this looks like

ILLUSTRATIVE EXAMPLE

A mailing intermediary changes a message and the final receiver accepts it based on its own trust assessment. That acceptance is not a new aligned signature from the original domain.

A mistake to avoid

ARC presence is not a universal bypass. The receiver decides whether to trust the intermediary and how to handle the message.

Keep the result in context

DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.