DMARC alignment

The requirement that the domain a message authenticated as (via SPF's envelope sender or DKIM's signing domain) matches the domain in the visible From header. Without alignment, a message can pass SPF or DKIM for one domain while displaying another, so DMARC treats such passes as failures. Alignment can be strict (exact match) or relaxed (same organisational domain), configured with the aspf and adkim tags.

An unhandled error has occurred. Reload 🗙