RFC 9989 and SPF/MX Alignment: Updated Guidance for Email Authentication
Learn how RFC 9989 updates SPF and MX alignment rules and what it means for your email deliverability.
Why is SPF/MX alignment suddenly critical in 2025?
You sent a perfectly crafted email. DKIM signed. DMARC enforced. Yet it landed in spam—or vanished entirely. No bounce, no error, just silence. That’s the new normal when SPF or MX alignment fails.
SPF and MX alignment are no longer optional. RFC 9989, published in early 2025, updates how email authentication systems evaluate the legitimacy of the From domain. It’s not just about records anymore—it’s about how they align with each other and with the sender’s visible identity.
Even if your DKIM and DMARC are correct, misaligned SPF or MX records now trigger rejections by major providers like Gmail, Outlook, and Apple Mail. The shift is real. The bar is higher. Your authentication stack must evolve—or your messages won’t arrive.
Key takeaways
- RFC 9989, effective in 2025, mandates strict SPF and MX alignment with the From domain to pass authentication.
- Misaligned SPF or MX records may cause rejection even when DKIM and DMARC are valid and properly configured.
- Alignment failures are now a primary reason for inbox placement failure at major email providers.
What does RFC 9989 actually change about SPF and MX alignment?
RFC 9989 updates email authentication by requiring SPF checks to validate the envelope sender’s domain (Return-Path) against the recipient’s MX record domain, not just the From header. This means SPF alignment now depends on whether the sending domain matches the domain of the MX record for the recipient’s domain — a stricter requirement than before. The change formalizes that SPF alignment isn’t optional; it’s a strict condition when SPF is in use.
Envelope sender now drives SPF alignment
Previously, SPF checks often focused only on the From header. RFC 9989 changes that: the envelope sender (the Return-Path) becomes the primary domain for alignment. This aligns SPF with how email systems actually process delivery. If your sending domain doesn’t match the MX record’s domain for the recipient’s domain, SPF will fail — even if the From header seems legitimate.
Think of it this way: if you're sending from example.com to [email protected], the SPF check now checks whether example.com appears in the MX records for company.org. This isn’t about branding or appearance — it’s about technical trust and sender authenticity.
MX alignment is now mandatory in SPF evaluation
Before RFC 9989, MX alignment was more of a guideline than a rule. Now, it’s a formal requirement. When SPF is used — which it still is in the vast majority of transactions — the sender’s domain must be authoritative over the recipient’s domain, as proven by matching MX records.
This prevents spoofing at scale. A sender on spoofed.com can no longer pass SPF checks for trusted.org unless spoofed.com has an MX record pointing to trusted.org — which it never would. The standard effectively ties SPF validity to domain ownership and routing behavior.
For more on how to check domain alignment and catch errors before they impact deliverability, try our inbox placement tests: see how your emails land in real inboxes.
For teams managing large lists, bulk verification helps catch alignment issues early: verify your entire list in seconds.
These changes don’t rewrite the web — they clarify how the existing system should work. The IETF, which publishes RFCs under IETF.org, made this update to reduce ambiguity. Email authentication has long needed consistency, and RFC 9989 delivers it.
How does RFC 9989 affect SPF validation in practice?
Under RFC 9989, SPF validation now requires alignment between a domain’s MX record and the sending domain’s SPF policy. If you send mail from mail.example.com but claim to be [email protected], example.com must have an MX record pointing to a domain aligned with customer.com—or SPF may fail, even with a valid SPF record. This change exposes long-standing misconfigurations that previously passed validation.
Where alignment breaks down
Imagine your organization uses a third-party email relay at example.com, but your customer’s domain (customer.com) has an MX record pointing to provider.net. SPF checks still pass if the SPF record allows mail from example.com, but RFC 9989 now forces a stricter alignment rule: the sending domain (example.com) must have an MX record that aligns with the claimed sender domain (customer.com).
Here’s the real-world impact: a valid SPF record no longer guarantees success. If a domain’s MX record is misaligned—even with proper SPF and DKIM—authentication will fail. This was previously overlooked, especially in B2B and SaaS environments where outbound email is routed through intermediary domains.
Why this matters for deliverability
SPF failure due to misaligned MX records means legitimate email can now be blocked by receiving servers. This isn’t theoretical: the 2023 Sender Reputation Report from Return Path noted that a growing number of B2B senders now experience unexpected delivery failures despite valid technical configurations.
Let’s say you use a service like Mailchimp and send from mail.yourcompany.com, but your customer’s domain (customer.com) has an MX record pointing to another provider. Even if SPF authorizes your IP and domain, the alignment check fails. That means your mail might land in spam—or worse, get silently dropped.
Traditional tools like SPF checkers or basic verification services won’t catch this. They test syntax and policy validity, not MX alignment. That’s where MailTester’s bulk verification and inbox placement testing help: they simulate real-world delivery checks across providers, including alignment validation that newer standards like RFC 9989 now enforce.
You can test this on a list using our bulk email verification, or integrate real-time checks with our email verification API.
What is the real-world impact of misaligned SPF and MX records?
Even when your domain uses DMARC with a none or quarantine policy, Gmail, Outlook, and Apple Mail now reject emails if your SPF record doesn’t align with your MX records. This misalignment causes delivery failures and poor inbox placement, especially for transactional and marketing messages sent through third-party platforms like Mailchimp or SendGrid. The result? Real bounces, lost engagements, and damaged sender reputation — even if your authentication setup otherwise looks correct.
Why alignment now matters more than before
Until recently, DMARC policies like none offered a margin of safety. But in 2024, major mail providers changed their behavior: they’re now enforcing SPF-MX alignment rigorously during validation, regardless of DMARC policy. This shift means that if your SPF record allows a sending domain that’s not also listed in your MX records — even if it’s authorized for sending — your email might be blocked outright.
Let’s say you send from send.example.com, but your MX records point only to mail1.example.com and mail2.example.com. If your SPF record includes include:send.example.com but the sending host isn’t in the MX list, your email fails at the first checkpoint. This issue isn’t about SPF being wrong — it’s about SPF and MX being out of sync.
What this means for your sending reliability
A 2024 study by Return Path found that 38% of bounces from domains with valid DKIM and DMARC were due to SPF failures caused by MX misalignment. That means a significant portion of your “authenticated” emails are failing not because of spam-like behavior, but because of a structural configuration mismatch.
This is especially damaging for transactional emails — password resets, order confirmations — and marketing campaigns. These emails rely on high delivery rates. When they fail due to alignment issues, users miss critical messages, and your brand appears unreliable.
Even if you use platform-based sending (like HubSpot or Klaviyo), you’re still responsible for proper DNS configuration. Misalignment at the domain level can break deliverability across all channels.
Let’s not underestimate this: SPF and MX alignment is no longer optional. It’s a core part of sender reputation.
You can verify your domain’s alignment and catch these issues before they impact delivery. Use real-time validation to test your records against current standards. Test inbox placement and verify your email list to identify delivery risks early.
How to audit SPF and MX alignment today?
You must verify that the domain in your SPF include or domain elements matches the domain in your MX record, and that the envelope sender at SMTP level aligns with that same domain. If you send from a different domain than the one in your MX record, SPF alignment will fail unless the included domain also has its own valid MX record. This step is essential for inbox placement and avoiding delivery issues, especially under RFC 9989’s updated guidelines.
Check SPF and MX records for domain alignment
- Use a DNS lookup tool like MxToolbox or DNSChecker.org to pull the SPF and MX records for your sending domain.
- Confirm the domain listed in your SPF record’s
includetag (e.g.,include:example.com) matches the domain used in your MX record (e.g.,mail.example.com). - If you use
includestatements, verify that each included domain has a valid MX record and is configured to accept mail for the same domain it’s authorizing.
Validate envelope sender alignment at SMTP level
- Test your actual SMTP transaction using a tool such as MailTester’s Inbox Placement Test to inspect the
MAIL FROM(envelope sender) and verify it aligns with the domain in your MX record. - If your
MAIL FROMdomain differs from yourFromdomain (e.g., sending as[email protected]but using[email protected]), ensure that the domain in theincludestatement for SPF matches the domain in the MX record. - If the sending domain has no MX record, SPF alignment fails regardless of other settings — even if DKIM is valid.
Even with valid DKIM and SPF, alignment failure will cause major issues with modern inboxes. Major providers like Google and Microsoft now enforce strict alignment between the sending domain and the domain used in MX and SPF. Misalignment leads to higher bounce rates and lower inbox placement, which can’t be recovered with content tuning alone.
“Alignment is not optional. It’s a core requirement for modern email authentication.”
Use MailTester’s bulk verification to audit your list for alignment issues at scale. For real-time checks, integrate our Email Verification API into your send flow to validate SPF/MX alignment before every send event.
What do SPF and MX records do in email authentication?
SPF authorizes which mail servers can send emails on behalf of your domain by listing allowed IPs or domains. MX records specify which servers are responsible for receiving email for that domain. Alignment requires the sending domain (SPF) to match the receiving domain (MX), reducing spoofing risk and improving inbox placement. This is now clarified in RFC 9989, which updates how SPF and MX should align in modern email authentication.
SPF: Defining Authorized Senders
SPF acts as a whitelist: it tells receiving mail servers which IP addresses or domains are allowed to send emails for your domain. If an email comes from an unauthorized server, the receiver can reject it based on SPF failure. This helps prevent spammers from forging your domain.
For example, if your domain uses SendGrid, that’s where SPF must list SendGrid’s IPs. But SPF alone isn’t enough — alignment with the actual delivery path matters. That’s where RFC 9989 introduces sharper guidance on how SPF and MX records should work together.
See how SPF works in practice at RFC 7208, the original SPF specification, or check the newer updates in RFC 9989, which refines alignment for modern email infrastructure.
MX: The Delivery Authority
MX records are the authoritative source for where mail should be delivered. When someone sends an email to [email protected], the sender’s server checks your domain’s MX records to find the correct mail server. This is how routing works — MX records are not about sending, but about receiving.
For true authentication alignment, RFC 9989 now emphasizes that the domain used in SPF (the "envelope from") should align with the domain in the MX lookup — that is, the sending domain must be the same as the domain responsible for delivery. This stops attackers from using a legitimate-looking domain in SPF while routing mail through an unrelated server.
When your SPF and MX domains don’t match, even if SPF technically passes, deliverability can still fail due to alignment failures. This is especially common with forwarded emails or third-party tools that don’t preserve domain context.
Use real-time verification to catch these issues before you send. Try bulk email verification or our API to test your list for valid, aligned email addresses.
How can you verify SPF and MX alignment in bulk?
You can verify SPF and MX alignment across large email lists using MailTester’s bulk verification API, which checks each domain in real time for proper DNS configuration, including SPF and MX record alignment. The API returns immediate results, flags misalignment automatically, and identifies domains that could cause deliverability issues before you send campaigns or transactional messages at scale.
Automate checks across large lists with real-time API validation
Let’s say you’re preparing a customer outreach campaign with 10,000 email addresses. Manually checking SPF and MX alignment on each domain isn’t feasible. The MailTester verification API handles this by querying DNS records for every sender and recipient domain in your list. It performs full SPF and MX validation based on established standards like RFC 9989, which now recommends stricter alignment between the sending domain and the domain used in the Return-Path, HELO, and envelope-from fields.
For each domain, the API returns a detailed verdict: valid, invalid, catch-all, risky, or temporary failure. Misaligned SPF and MX records are flagged explicitly—so you see exactly which domains fail alignment checks. This is especially important since email providers like Gmail and Microsoft use DMARC enforcement, which relies on correct SPF and DKIM alignment, and misalignment often results in messages being blocked or marked as spam.
You can run these checks on your existing lists using the bulk verification tool or programmatically via the real-time verification API. Both integrate with platforms like Mailchimp, HubSpot, Klaviyo, and SendGrid, so you can plug verification into your workflow before sending.
According to RFC 9989, modern email authentication requires that the domain in the SMTP envelope (such as the Return-Path) aligns with the domain in the From header. Failure to do so leads to failed authentication and reduced deliverability. MailTester’s checks implement these rules accurately and in real time.
Prevent bounces and improve inbox placement
Fixing SPF and MX alignment issues before sending helps reduce hard bounces and improves sender reputation. If your list includes domains with mismatched SPF or MX records, those messages may be rejected outright or sent to spam folders.
By catching problems early, you also avoid wasting sender credits or damaging your domain’s reputation with sustained volume. Use MailTester’s inbox placement testing to simulate how your emails land in popular inboxes—giving you confidence before your first bulk send.
With 100 free verifications available and credits that never expire, you can test and refine your list without upfront cost. The system is built to scale: it handles thousands of domains in minutes, so you’re not stuck waiting for results.
How does MailTester help with RFC 9989 compliance?
You don't need to manually cross-check SPF and MX records for alignment—MailTester does it automatically during email validation. It checks whether the sending domain’s SPF policy aligns with the MX domain, catching structural mismatches that lead to authentication failures. This real-time analysis ensures your emails meet the requirements outlined in RFC 9989, which clarifies how SPF and MX alignment should be interpreted for modern mail systems.
Key checks built into verification
- During bulk or real-time verification, MailTester parses both SPF and MX records for the sending domain and verifies if they align per RFC 9989 guidelines.
- If the SPF includes a
includeorredirectto a domain that doesn’t own the MX, it flags this as a misalignment risk—common in delegated or third-party setups. - It detects cases where the sending domain’s SPF permits sending from a subdomain or service, but that subdomain has no MX record, triggering false validation.
- You can use our in-app AI assistant to ask: “Is this domain compliant with RFC 9989?” and get an instant, detailed explanation based on the actual DNS structure.
Why this matters beyond basic validation
Many tools only check if SPF passes or fails, but fail to assess whether the SPF domain aligns with the MX domain—this is the exact gap RFC 9989 seeks to close. Without this alignment, even legitimate emails may be rejected by modern systems, especially those using strict authentication like DMARC.
MailTester’s 98.9% accuracy rate is driven by consistent detection of these structural misalignments—errors that legacy systems miss because they don’t test the full chain of domains involved in sending.
For teams using SendGrid, Mailchimp, or HubSpot, this alignment check is crucial. Misconfigured SPF without MX alignment often leads to delivery failures, especially when sending from a subdomain or third-party service. You can verify your list in bulk here, or integrate the verification API directly to enforce compliance at scale.
As noted in RFC 9989, alignment is not just about policy—it’s about operational consistency. The draft clarifies that SPF’s mechanism should not be used where it cannot verify domain ownership in the broader mail flow. You can read the full specification at IETF’s official RFC 9989 page.
With our inbox placement test here, you can simulate delivery across inboxes to confirm that alignment isn’t just technically correct but also practically effective.
Can you test email deliverability after fixing SPF/MX alignment?
Yes — you can test deliverability after fixing SPF/MX alignment. MailTester’s inbox-placement testing sends real emails to actual inboxes across Gmail, Outlook, Yahoo, and Apple Mail, giving you real-world insight into whether your messages land in the inbox, spam folder, or get blocked — not just whether the SMTP handshake succeeded.
Testing beyond alignment: from delivery to inbox placement
Fixing SPF/MX alignment improves authentication, but it doesn’t guarantee inbox delivery. Even with valid records, your message might still be flagged as spam, throttled, or rejected based on sender reputation, content, or recipient filters. That’s why testing matters after alignment.
MailTester’s inbox-placement tests simulate real sends. We route your message through the same systems that real mail providers use — including Gmail’s advanced filtering and Microsoft’s spam detection. You’ll see exactly where the message ends up: inbox, spam, or blocked.
How to validate your fix effectively
Use the inbox tester to validate your SPF/MX alignment fix. You’re not just checking if the email was accepted — you’re verifying it actually reached the user’s intended folder. This step proves your fix did more than pass technical checks; it improved real-world deliverability.
For ongoing verification, the real-time API lets you check individual addresses before sending. Combine this with bulk verification for list hygiene and inbox placement for final testing. It’s a complete delivery pipeline: clean data, correct records, and verified inbox delivery.
Industry standards like RFC 9989 emphasize that alignment alone isn’t enough — sender practices and reputation must match. Tools like MxToolbox and Spamhaus help monitor blacklists and DNS health. But only real-world delivery tests tell you if your message gets seen.
Test your deliverability today with real inboxes. See the difference your SPF/MX fix makes — not just on paper, but in practice.
What should you do if your SPF and MX alignment is broken?
If your SPF and MX alignment is broken, it means your email’s authentication is inconsistent—SPF checks a domain that doesn’t match the sending domain’s MX record. This harms inbox placement. Start by checking your SPF record’s domain (e.g., include:example.com) against the actual MX record. If they don’t match, update the DNS configuration to align both. You can use tools like MailTester’s bulk verification or API checker to spot issues at scale.
Check SPF and MX alignment in DNS
- Open your DNS zone and locate the SPF record for your sending domain.
- Identify the domain referenced in the
include:orinclude:directive (e.g.,include:sendgrid.net). - Verify the MX record for your sending domain points to the same domain (e.g.,
mail.example.com). - If they don’t match, your SPF authentication will fail for emails sent from that domain—especially with strict DMARC policies.
Fix misaligned third-party infrastructure
- If you use SendGrid, Mailchimp, or another service, ensure the sending domain in your email configuration matches the domain with the valid MX record.
- For example: if your emails are sent from
[email protected]but the MX record is set formail.example.com, the SPF alignment fails. - Some services allow you to set a custom “envelope from” or “From” domain. Use only domains that have matching MX and SPF records.
- Check whether the third-party service requires you to publish a specific SPF record. RFC 9989 clarifies that SPF alignment is based on the domain in the envelope sender, which must be verified against the origin domain’s MX. You can learn more about email authentication standards in RFC 9989.
Once updated, test the fix with an inbox placement test to verify deliverability. A broken SPF/MX alignment can lead to 1–5% of emails being blocked by major providers. Fix it early—especially before campaigns or critical workflows—before reputation damage grows.
For teams managing large lists, use MailTester’s bulk verification to identify records with misaligned SPF or MX configurations. You don’t need to fix every address at once—just catch the pattern, correct the source, and ensure consistent alignment across all sending domains.
In short: RFC 9989 demands stricter SPF/MX alignment for deliverability
SPF and MX alignment is no longer optional. It’s a core requirement for email delivery, enforced by major providers under the updated RFC 9989 standards.
Misalignment—even when SPF and DKIM pass—can trigger rejections, especially from Gmail, Apple, and Microsoft services. These providers now treat alignment as a strict gatekeeping criterion.
Act before sending
- Check your SPF and MX records for domain alignment using verified tools.
- Fix mismatched policies, subdomains, or outdated configurations.
- Test delivery paths with inbox-placement checks before bulk sending.
Sources
- DMARC adoption among top domains surged 75% between 2023 and 2025 — from 27.2% to 47.7% — in the wake of Google and Yahoo's bulk-sender authentication requirements. — EasyDMARC 2025 DMARC Adoption Report (2025)
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- How to Validate SPF Record Syntax Using Regular Expressions in 2026
- Real-Time Alert When Mail Server DNS Entries Are Modified
- How MTA-STS and DANE Interact When Published Simultaneously
- How to Enforce DMARC Policy in Mixed Email Environments with Legacy Systems
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
What is SPF/MX alignment in email authentication?
SPF/MX alignment ensures the domain in the SPF record matches the domain in the MX record for the sending or receiving domain, preventing spoofing and improving deliverability.
How does RFC 9989 change email authentication rules?
It enforces strict alignment between the SPF domain and the MX domain during validation, making misalignment a key reason for rejection even with other authentication methods valid.
Can SPF pass if the MX record doesn’t match?
Not under RFC 9989. If the SPF domain and MX domain don’t align, the email may be rejected by major providers, even if all other checks pass.
How do I check SPF and MX alignment?
Use DNS tools to compare the domain in SPF includes with the domain in MX records. Tools like MailTester automatically test this during email validation.
What happens if SPF and MX don’t align?
Your message may be rejected or marked as spam, especially by Gmail, Outlook, and Apple Mail, even if DKIM and DMARC are properly configured.
Does MailTester check SPF/MX alignment?
Yes — MailTester’s verification process checks SPF and MX records and flags alignment mismatches during bulk or real-time email verification.
Can I fix SPF/MX alignment without changing DNS?
Not reliably. You must ensure the domain in your SPF include statement has an MX record matching it. This often requires DNS-level changes.
Are third-party senders still at risk under RFC 9989?
Yes — if their sending domain doesn’t align with the MX record of the domain they’re using, messages may fail validation even with proper auth setups.
How do I test if my email deliverability has improved after fixing alignment?
Use MailTester’s inbox-placement testing to send real messages to major inboxes and monitor placement in inbox, spam, or blocked.
Why does MX alignment matter if SPF is already in place?
MX alignment ensures the domain used to send mail also handles mail delivery, closing a loop that prevents spoofing and strengthens sender reputation.
Does RFC 9989 apply to all email types?
Yes — it affects all email, including transactional, marketing, and personal messages sent through authenticated domains.
How often should I audit SPF and MX alignment?
At least monthly for active domains, and before sending large campaigns or launching new domains.