DIAGNOSTIC PLAYBOOK

ARC pass does not automatically mean DMARC pass

ARC preserves authentication assessments across intermediaries, but its chain result is separate from a current DMARC result. Receivers decide whether an intermediary's evidence is trustworthy enough to influence handling.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. List the ARC sets and their instance numbers, keeping the chain result separate from SPF, DKIM and DMARC.
  2. Identify the intermediary that sealed the relevant assessment.
  3. Use final receiver results and policy handling to understand whether ARC influenced acceptance.

What this looks like

ILLUSTRATIVE EXAMPLE

A forwarded message has a valid ARC chain but fails current DMARC. A receiver may still accept it through local policy rather than reporting a new DMARC pass.

A mistake to avoid

Any sender can participate in adding authentication-related text. A valid chain is not the same as universal trust in the chain's operators.

Keep the result in context

Inspect the original raw message rather than a forwarded screenshot. Headers can contain private addresses, message identifiers and routing information, so redact a separate copy before sharing. Give the most weight to results added by your own trusted receiving infrastructure.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.