DIAGNOSTIC PLAYBOOK
DMARC passes while SPF fails: follow the DKIM result
DMARC can pass when SPF fails if a valid DKIM signature aligns with the visible From domain. Read the mechanisms separately before treating this combination as contradictory.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Find the receiver's SPF, DKIM and DMARC results in the same trusted header set.
- Compare the passing DKIM signing domain with the visible From domain under the applicable alignment mode.
- Investigate the SPF failure separately to understand whether forwarding or a missing authorization caused it.
What this looks like
ILLUSTRATIVE EXAMPLE
A forwarded message arrives from an IP outside the original SPF policy. Its original aligned DKIM signature survives, allowing DMARC to pass.
A mistake to avoid
A DMARC pass does not erase an SPF configuration problem. Direct mail from a legitimate service should still be checked on its own path.
Keep the result in context
DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.