DIAGNOSTIC PLAYBOOK

DMARC passes while SPF fails: follow the DKIM result

DMARC can pass when SPF fails if a valid DKIM signature aligns with the visible From domain. Read the mechanisms separately before treating this combination as contradictory.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Find the receiver's SPF, DKIM and DMARC results in the same trusted header set.
  2. Compare the passing DKIM signing domain with the visible From domain under the applicable alignment mode.
  3. Investigate the SPF failure separately to understand whether forwarding or a missing authorization caused it.

What this looks like

ILLUSTRATIVE EXAMPLE

A forwarded message arrives from an IP outside the original SPF policy. Its original aligned DKIM signature survives, allowing DMARC to pass.

A mistake to avoid

A DMARC pass does not erase an SPF configuration problem. Direct mail from a legitimate service should still be checked on its own path.

Keep the result in context

DMARC connects the visible From domain to a passing, aligned SPF or DKIM identity. A DNS policy is an instruction to receivers, not a delivery receipt. Use message results and aggregate reports together, and identify legitimate services before tightening a policy.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.