Skip to main content
DMARC 3 min read

Why an email sent by a third-party vendor passed SPF/DKIM checks but failed the DMARC check?

Brad Slavin
Brad Slavin General Manager
Updated May 23, 2025

Quick Answer

An email can pass SPF and DKIM individually but still fail DMARC because DMARC adds identifier alignment on top. SPF checks the RFC5321.MailFrom domain and DKIM checks its d= signing domain, but DMARC requires that one of those domains also align with the visible From-header domain. In strict mode the domains must match exactly; in relaxed mode they only need to share an organizational domain. So if a vendor sends as manufacturernewsletter.com on behalf of manufacturer.com, SPF and DKIM can pass against the vendor domain while DMARC fails because nothing aligns with the From-header. Fix it by signing with a DKIM key under your own domain (vendor handles a CNAME) or by setting the Return-Path to a subdomain of yours that authorizes the vendor in SPF.

Why an email sent by a third-party vendor passed SPF/DKIM checks but failed the DMARC check?

Email sent by a third-party

DMARC helps prevent spoofed emails from bypassing spam filtering, but it’s just one part of a broader anti-spam strategy. Not all DMARC reports are equal; some show detailed recipient responses, while others only indicate success or failure. Understanding why a message failed is as important as knowing if it did.

When SPF is used, it checks the domain in the RFC5321.MailFrom (also called “ReturnPath”) to find the SPF record. After a successful SPF check, the receiver gets an “Authenticated Identifier,” which is the RFC5321.MailFrom domain.

This article will explore why DMARC fails for third-party email senders.

spam filtering

Why does DMARC fail for emails sent by third-party vendors?

If there are any third-party vendors that are associated with your business and are required to send emails on your behalf, then you must enable SPF, DKIM, and DMARC for your email-sending domain. There are two ways to do this– either you ask your vendor to handle email authentication on your behalf, or you handle everything. 

If emails sent from the Gmail domain are failing the DMARC test, check your SPF record to see if you have included _spf.google.com. Receiving servers may not recognize Gmail as your authorized sending source, causing emails to fail the DMARC check altogether. 

We have listed below another possible reason for this failure.

Identifier alignment issue

Identifier alignment is a relatively new DMARC element that requires the domain in the ‘From’ header of an email to match or align with the domain used in the SPF and/or DKIM authentication checks. There are two alignment modes: strict and relaxed.

If you have applied strict alignment, then the domain in the “From” header must match exactly with the domain in the SPF “Mail From” or the DKIM “d=domain”.

As for the relaxed alignment, the domain in the “From” header must be a subdomain of the domain used in SPF or DKIM or vice versa.

Identifier alignment is necessary because anyone can set up SPF and DKIM for any email.

For example, a threat actor could create the domain personal.net to spoof emails from manufacturer.com, and even if SPF and DKIM pass, it doesn’t mean the email is genuinely from manufacturer.com.

Email receivers can’t keep track of which domains are associated with each other—they need to process emails quickly without figuring out the details. For instance, if your email service provider uses “manufacturernewsletter.com” for SPF and DKIM while sending emails for manufacturer.com, receivers can’t tell if manufacturernewsletter.com is legitimate, a phishing site, or related to manufacturer.com.

Identifier alignment ensures that email authentication technologies are relevant to the actual content of the email.

Email spoofing

We can help

We at DuoCircle are dedicated to bolstering email security for domain owners so that they can dodge email-based cyber menaces. Contact us to avoid DMARC failures due to folly or genuine technical issues. We take care of everything for you.

Topics

DMARCemail securityUpdates
Brad Slavin
Brad Slavin

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.