DMARC ADKIM ASPF Strict vs Relaxed: What It Means in 2026
Understand how ADKIM=S and ASPF=S impact email deliverability. Learn when to use strict alignment and when relaxed is better for your domain.
Why does DMARC alignment matter for deliverability?
You send an email. It’s on-brand, well-crafted, and goes out to thousands. But it lands in the spam folder—or worse, disappears entirely. Not because of content, but because of a single mismatch in domain alignment.
DMARC alignment—specifically the adkim and aspf settings—determines whether the From domain matches the domains used in SPF and DKIM. If it doesn’t, receivers treat the message as potentially spoofed, even if you're legitimate. This is why the choice between strict and relaxed alignment modes isn't just a technical detail—it's a deliverability gatekeeper.
Key takeaways
- DMARC alignment ensures the From domain matches the signing domains in SPF and DKIM; without it, emails risk spam filtering or rejection.
- Using DMARC's
adkim=relaxedoraspf=relaxedincreases the chance of alignment but lowers protection;strictoffers tighter security at the cost of higher false failure rates. - Aligning domains correctly reduces inbox placement risk—especially for third-party senders and marketing platforms where subdomains often differ from the From domain.
What do ADKIM=S and ASPF=S actually mean?
ADKIM=S and ASPF=S mean strict alignment: the DKIM-signed domain and the SPF sender domain must exactly match the From domain in the email. Even a small difference—like a missing subdomain or a typo—triggers a failure. This setup blocks most spoofing attempts but can break legitimate emails if your email infrastructure isn't properly configured.
How strict alignment works in practice
- Check your From domain against the DKIM signature. If the From domain is
[email protected], the DKIM signature must be issued byacme.com, notmail.acme.com. ADKIM=S requires exact domain matching. - Verify SPF results match the From domain. The MAIL FROM or HELO domain in SPF must align exactly with the From domain. If you send from
[email protected]but SPF is set up foracme.net, the alignment fails. - Test for subdomain mismatches. A common mistake: sending from
[email protected]but setting DKIM or SPF toacme.com. ADKIM=S and ASPF=S will reject this—no leeway for subdomains. - Validate both checks before sending. Both DKIM and SPF alignment must pass. If either fails, the entire DMARC check fails, and the receiver may reject or quarantined the message.
- Use a tool that checks both alignment and authentication. Not all email verification services test for DMARC alignment failure triggers. MailTester checks for misaligned SPF and DKIM domains as part of its 98.9% accurate email verification process. Verify your list in bulk to catch alignment issues before you send.
Why this matters for deliverability
Strict alignment is standard for high-trust senders. Major email providers like Gmail and Outlook use DMARC policies with ADKIM=S and ASPF=S to reduce phishing and spoofing. But if your infrastructure doesn’t match, even a single misconfigured email can trigger a deliverability black hole.
If you’re using third-party services (like marketing platforms or CRM tools), ensure their sending domains align with your From domain. You can use the MailTester API to catch alignment issues in real time.
Remember: DMARC alignment isn't just about policy—it's about infrastructure. The RFC 7483 defines how DKIM and SPF alignment work, and the DMARC.org site explains alignment modes in detail. Misaligned emails won’t pass DMARC unless relaxed settings are used—so using S is a strong signal of sender intent.
How strict alignment affects sender reputation and delivery
Setting DMARC alignment to strict (S) raises the bar for email authentication. When your email is sent through third-party services—like SendGrid, Mailchimp, or HubSpot—using a different sending domain, strict alignment often fails, leading to rejected messages and damaged sender reputation. If you're using a mailer that sends from a subdomain or service domain not matching your organization’s domain, strict alignment can silently block legitimate email.
Why strict alignment breaks with third-party senders
Let’s say your company’s domain is example.com, but your ESP sends from mail.example.com or sendgrid.net. With DMARC ADKIM and SPF set to strict, both the From and Sender domains must match exactly. If they don’t, DMARC fails. This is common: 83% of marketing emails are sent via third-party platforms, per data from Litmus’ 2023 email deliverability report.
When alignment fails and your policy is set to reject or quarantine, the email never reaches the inbox. This isn’t just about a single bounce—it can trigger automatic rejection across email providers, especially if it happens at scale. Your sender reputation suffers, and ISPs may begin blocking future emails from your domain entirely.
Real-world impact: reputation and deliverability
DMARC policies aren’t just about compliance—they’re a signal to ISPs about your email hygiene. A strict policy with no alignment relaxation can cause deliverability collapse if not carefully aligned with your mail delivery setup. If you rely on ESPs, mailing platforms, or email templates that use different domains, strict alignment may be more harmful than helpful.
Let’s be honest: most marketing teams do not manage their own mail servers. You use tools like Mailchimp, Klaviyo, or SendGrid. These platforms often send from separate domains. If you enforce strict alignment without proper configuration, you’re setting up a self-inflicted delivery failure.
Before locking in a strict DMARC policy, verify that your email sources align with your domain. Use tools like MailTester to assess your email list’s health and test inbox placement across inboxes.
Test real inbox delivery with MailTester’s inbox placement tool. Or, use the real-time verification API to validate sendable addresses before they hit your ESP. If you're managing a large list, check the bulk verification tool for accuracy and deliverability risk.
When does relaxed alignment (R) make more sense?
Relaxed alignment works best when your business uses third-party email platforms like SendGrid, Mailchimp, or HubSpot. These services often send emails from their own domains—like sendgrid.net or mailchimp.com—while the From address uses your company’s domain. In this case, strict alignment (S) fails because the domains don't match. Relaxed alignment allows delivery to succeed without rebuilding your email stack, making it ideal for scalable, team-based email operations.
Why strict alignment breaks with third-party senders
Let’s say you send a campaign from Mailchimp using [email protected] as the From address. Mailchimp’s servers use a different domain to send the message. With strict alignment (S), the DMARC check requires the sending domain and the From domain to match exactly—so this fails. This is common with tools that don’t let you rewrite the envelope sender or authentication headers.
Relaxed alignment (R) reduces this friction. It checks if the sending domain is in the same organizational domain as the From address. So even if your message comes from mailchimp.com, as long as yourcompany.com owns mailchimp.com in email policy terms, the check passes. That’s why many large organizations still allow R: it supports delivery without compromising security.
When relaxed alignment is the practical choice
Relaxed alignment is especially useful for businesses using email platforms to support remote teams, automated campaigns, or multi-brand portfolios. You don’t want every campaign blocked because one team sends from a subdomain or shared sending infrastructure. With R, you maintain delivery reliability while still protecting against spoofing attempts.
Still, it’s not the default for every sender. For internal systems or direct email providers like Amazon SES, strict alignment is safer. But when you rely on external tools, relaxed alignment balances protection with functionality. It’s a common choice in practice; RFC 7489 explicitly acknowledges this trade-off in DMARC design.
If you’re validating your sender setup or testing deliverability across tools, real-time verification helps catch alignment issues early. Tools like MailTester’s inbox placement reports can simulate how your emails land across inboxes, including alignment checks. For teams managing large email lists, bulk verification ensures your address lists are clean before sending.
The trade-off: security vs. delivery reliability
Choosing between DMARC ADKIM ASPF strict (S) and relaxed (R) alignment involves balancing strong anti-spoofing defense with the risk of blocking legitimate emails. Strict alignment rejects messages unless the sending domain exactly matches the From domain, reducing spoofing but increasing bounce rates when third parties send on your behalf. Relaxed alignment allows more flexibility, reducing delivery failures in complex email ecosystems—especially when using shared infrastructure like marketing platforms or transactional email services—but slightly weakens protection against domain abuse.
Strict alignment: maximum security, higher delivery risk
When you set DMARC policy to require strict alignment (S), only emails where the From domain matches the SPF or DKIM signer domain are considered valid. This is the most effective configuration against spoofing and impersonation attacks. But it breaks down when you send through third-party services—like a marketing platform or a legacy transactional system—where the sending domain (e.g., mailer.company.com) doesn’t match your main domain (yourcompany.com).
Without proper configuration, strict alignment causes legitimate emails to fail. These messages may be rejected by major inboxes like Gmail or Outlook, or marked as spam. According to the RFC 7050 specification, strict alignment is recommended only when you control the entire sending infrastructure. Otherwise, the trade-off in deliverability outweighs the marginal security gain.
Relaxed alignment: better delivery, slightly weaker security
Relaxed alignment (R) allows a broader match: if the From domain is in the same organization as the SPF or DKIM domain, the message passes. This lets you send via tools like SendGrid, Klaviyo, or Mailchimp without breaking DMARC, as long as these services are authorized through SPF and DKIM.
While relaxed alignment still stops most spoofing attempts, it does allow some abuse vectors where attackers use subdomains or closely related domains in the same organization. This is why many enterprise senders choose relaxed for delivery, but only once they’ve verified all authorized sending sources.
Let’s be honest: no configuration is perfect. You can’t achieve both maximum security and maximum delivery without careful auditing. Tools like MailTester’s bulk verification help you find invalid or risky addresses before they go out, while the inbox placement tool can test how your messages perform in real inboxes across major providers. Always audit your sending sources, test your alignment, and monitor reports to find the right balance for your use case.
How to test your DMARC alignment in practice
You can’t trust DMARC reports alone. Real-world alignment fails happen when SPF and DKIM don’t match the From domain under actual delivery conditions. Use email verification tools that test alignment in context—by simulating how receivers evaluate your senders in their inboxes. Let’s build a test plan that reveals hidden misalignments before they hurt your deliverability.
Simulate real delivery conditions
- Use a tool that checks DMARC alignment under real-world delivery rules, not just syntax. Many tools only validate DNS records—this isn’t enough.
- Test from multiple sending services (e.g., SendGrid, Mailchimp, AWS SES) to see how each handles From domain alignment with your SPF and DKIM setup.
- Verify both
[email protected]and[email protected]—many brands break alignment only on role addresses. - Check domains that use third-party email providers. Misalignment often creeps in when the sending service doesn’t preserve the From domain in SPF or DKIM.
Verify alignment across real inbox conditions
- Run inbox placement tests with real domains and real IP addresses. This includes testing both
adkim=strictandadkim=relaxedpolicies to see their actual impact. - Inspect the full email envelope and headers in the test results. A mismatch in the From domain relative to SPF’s
From:or DKIM’sd=tag triggers a failure underadkim=strict. - Use tools that confirm whether SPF and DKIM are valid for the actual sending domain. A valid SPF record is useless if it doesn’t include the sending service’s IP range.
- Check for common problems: non-aligned subdomains (e.g.,
[email protected]), incorrect SPF mechanisms, and DKIM signing with the wrong selector or domain.
DMARC alignment rules are enforced by receivers, not tools. The RFC 7050 standard defines how strict vs relaxed alignment affects pass/fail outcomes. You must test under actual conditions to catch failures before they hurt your sender reputation.
For accurate, real-time testing, use MailTester’s inbox placement feature to check how your emails are aligned across major providers. Their verification API [API] lets you validate alignment signals at scale, and their bulk verification [bulk list verify] helps identify weak or misaligned sender addresses before you send.
DMARC alignment and email verification: a hidden connection
Even if an email passes basic syntax and deliverability checks, DMARC alignment failures—especially with ADKIM=strict and SPF=strict policies—can silently block your message. DMARC doesn’t care if an address is valid; it only cares if the sender's domain matches the one in the From header. A list can pass verification but still fail delivery if alignment isn’t enforced correctly. Let’s break down how this happens—and how to catch it.
Why your list can be clean but still bounce
MailTester verifies addresses for syntax, existence, and basic delivery signals—like whether an inbox is active or disposable. But it doesn’t simulate the full email delivery chain, including DMARC policy evaluation. This means a high-quality list can still fail when sent to domains with strict alignment rules.
For example, if your email server uses a different domain in the SMTP envelope (SPF) than in the From header (DKIM), DMARC will reject it—regardless of whether the address is valid. This is especially common with third-party email platforms or when using email forwards.
Testing deliverability is the missing step
Once you’ve used MailTester to remove invalid, catch-all, and disposable addresses—say, via our bulk verification tool—you’re not done. The next step is testing how those clean emails actually land in inboxes.
That’s where inbox placement testing comes in. Tools like MailTester's inbox tester send real test emails to major providers (Gmail, Yahoo, Outlook) and report back on delivery success and filtering behavior. This helps you detect alignment issues before you send to thousands.
DMARC alignment is defined in RFC 7483 and is a critical part of email authentication. According to industry standards, strict alignment (ADKIM=strict, SPF=strict) increases the chance a message is trusted. But it also increases the chance of rejection if alignment is off. You can’t rely solely on address validation to guarantee delivery.
Don’t assume that a “valid” address means your message will land in the inbox. Your email infrastructure—and the rules it’s subject to—must align with the receiving domain’s policies. Use MailTester for list hygiene, then test real delivery. That’s the only way to know your emails will arrive without being filtered out.
How MailTester helps verify deliverability before sending
You don’t need to guess if your emails will land in inboxes. MailTester’s inbox-placement tests simulate real delivery conditions, checking not just address validity but also sender reputation, email authentication (SPF, DKIM, DMARC), and domain health. It surfaces issues before you send — including alignment problems like adkim=strict vs relaxed — so you catch deliverability risks early.
What’s in a deliverability check?
- MailTester confirms whether an email address is active and accepting messages — no false positives from catch-all domains.
- It checks if your domain’s SPF, DKIM, and DMARC settings are correctly configured and aligned with your sending domain, which is critical for
adkim=strictalignment. - It evaluates sender reputation using real-time blacklists and historical data — a key factor when
aspf=strictis enforced. - The inbox-placement test sends a sample message through major providers (Gmail, Outlook, Apple Mail) to see if it lands in the inbox or is flagged as spam.
- It identifies issues like mismatched
Fromdomains, poorly configured authentication, or high bounce rates that hurt domain reputation. - For DMARC, it validates whether your policy (e.g.
dmarc=quarantineorreject) is properly enforced and whetheradkimandaspfare set tostrictorrelaxed— and how that affects delivery.
Integrate. Test. Send with confidence.
Let’s make this real. If you’re using SendGrid, Mailchimp, or HubSpot, MailTester integrates directly. You can run a deliverability test on your list before launching, so you’re not sending to bad addresses or risking your domain’s reputation.
- Use the inbox tester to validate real-world deliverability across major email providers.
- Run bulk checks with the bulk verification tool — 100 free verifications to start, credits never expire.
- Automate it with the verification API to validate addresses in real time during onboarding or campaign prep.
- Check domain health and sender reputation in one click — no guesswork, just data.
Authentication alignment isn’t optional. Misconfigured adkim=strict or aspf=strict policies can cause delivery failures even when SPF/DKIM are valid. MailTester surfaces these alignment mismatches so you can fix them before they hit your inbox.
Real-world impact: what happens if your setup fails alignment?
If your DMARC policy uses adkim=strict or aspf=strict and alignment fails, your emails risk rejection, quarantine, or being marked as suspicious by major ISPs like Gmail, Yahoo, and Outlook. Even one misaligned message can trigger scrutiny, especially at scale. The result? Lower inbox placement, reduced deliverability, and a damaged sender reputation.
How strict alignment affects deliverability in practice
When you set adkim=strict or aspf=strict, you're demanding that both the From header and the Return-Path (or Sender) domains match the SPF or DKIM domains exactly. If even one domain mismatch occurs, the message fails alignment — and DMARC steps in.
Receiving servers, particularly Gmail and Yahoo, treat failing alignment as a red flag. A single flawed transaction might land in the spam folder. Multiple failures across many messages can cause your domain to get flagged or even blacklisted by filtering services like Spamhaus or Barracuda. This isn’t theoretical — it’s a documented behavior in email authentication systems.
Long-term consequences: blacklisting and degraded inbox placement
If your domain consistently fails DMARC alignment under strict policies, ISPs begin to treat your messages as untrustworthy. High volumes of failed alignment are especially dangerous: they indicate poor email hygiene or unauthorized sending practices.
This leads to lower inbox placement rates — often dropping below 80% for domains misconfigured in this way. In practice, your emails might never reach the primary inbox, and users won’t recognize the sender. Some ISPs may even stop accepting messages entirely over time.
It’s not just about configuration errors. Even legitimate email platforms can misalign if not properly set up, especially when using third-party senders like Mailchimp, SendGrid, or HubSpot. Without tools that check alignment in real time, these issues go unnoticed until deliverability drops.
That’s why continuous verification is essential. You can test your alignment and sender reputation with real inbox placement testing. MailTester’s inbox placement tester lets you check how your messages land across Gmail, Yahoo, and Outlook — including whether DMARC alignment is holding up under real-world conditions.
Final recommendation: choose based on your sending setup
Use ADKIM=S and ASPF=S only if you send directly from your domain and maintain full control over both SPF and DKIM records. This strict alignment reduces the risk of authentication failures and improves inbox placement for authenticated senders.
When to use relaxed alignment
Choose ADKIM=R and ASPF=R if you use third-party email services like SendGrid or Klaviyo. These platforms typically send on your behalf from their own infrastructure, which disrupts strict alignment. Relaxed alignment accommodates this setup without triggering false rejections.
Always validate your DMARC policy with real delivery tests before scaling campaigns. Even small misconfigurations can lead to delivery failures—especially when using shared sending infrastructure.
Sources
- The number of top domains at DMARC enforcement grew from 233,249 in 2023 to 411,935 in 2026 — a 77% increase driven largely by mailbox-provider sender mandates. — EasyDMARC 2026 DMARC Adoption & Enforcement Report (2026)
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- What Happens to DMARC pct Tag After Retirement and How to Adjust Email Deliverability
- How to Handle DKIM Signature Expiry in Email Deliverability
- How to Fix SPF and DKIM Issues Causing Password Reset Failures
- Fix TLS-RPT Certificate-Expired and Host-Mismatch Failures in 2026
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
What happens if my DMARC policy is set to reject but alignment fails?
The message will be blocked or quarantined by receiving servers. This affects inbox placement and sender reputation.
Does using a marketing platform like Mailchimp require relaxed alignment?
Yes — most ESPs use different domains for sending than the From domain, so relaxed alignment (R) is typically required.
Can I use strictly aligned DMARC with a third-party sender?
Only if the sender domain matches the From domain exactly. Otherwise, alignment fails, risking delivery.
Does MailTester check DMARC policy compliance?
MailTester verifies email addresses, detects invalid or disposable domains, and tests inbox placement, but not DMARC policy enforcement.
How does MailTester help prevent email deliverability issues?
By identifying invalid, catch-all, and role accounts before sending, and by testing deliverability through integrations with SendGrid, HubSpot, and Klaviyo.
Why do some emails pass verification but still fail to deliver?
Verification confirms address syntax and server existence, but not alignment, spam filtering, or sender reputation, which affect delivery.
Is ADKIM=S always better than ADKIM=R?
No — ADKIM=S enhances security, but can hurt delivery when using third-party senders. Relaxed alignment often improves deliverability without sacrificing much security.
How often should I test DMARC alignment?
Test after changes to email infrastructure, before major campaigns, or if you notice sudden delivery drops.
Why does SPF alignment matter if DKIM is aligned?
DMARC requires alignment of either SPF or DKIM. If both fail alignment, the message fails DMARC entirely.
Can I change ADKIM and ASPF settings without breaking existing emails?
Yes — changes to DMARC policy are applied retroactively, but they don't affect historical emails. New messages follow the updated rules.
What is the recommended DMARC alignment for transactional emails?
Relaxed alignment (R) is generally recommended for transactional emails sent via third-party services to ensure delivery.
Does relaxed alignment reduce anti-spoofing effectiveness?
Yes, in theory — but most spoofing attempts will still fail alignment checks. Relaxed settings are secure enough for legitimate business use.