DIAGNOSTIC PLAYBOOK
Resent-From is not the same as the DMARC From domain
Resent fields describe reintroduction of a message into transport and do not simply replace the ordinary From identity for DMARC. Examine the complete message instead of treating the most prominent resender field as the author.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Locate the original From field and the Resent field block separately.
- Read the trusted receiver's authentication results and the domains actually evaluated.
- Compare the resending workflow with an ordinary forward to understand its identity handling.
What this looks like
ILLUSTRATIVE EXAMPLE
A user resends a message and adds Resent-From under a different domain. That field does not by itself authenticate the original From domain.
A mistake to avoid
A mail client's presentation can hide or emphasize fields differently. Use raw headers for identity investigations.
Keep the result in context
Inspect the original raw message rather than a forwarded screenshot. Headers can contain private addresses, message identifiers and routing information, so redact a separate copy before sharing. Give the most weight to results added by your own trusted receiving infrastructure.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.