Aligning DKIM when a vendor sends on your behalf
CRM, billing and support tools often sign with their own domain. How to get vendor mail DKIM-aligned with your From domain before enforcing DMARC.

On this page(9 sections)
- Why vendor DKIM so often does not align
- Step 1: build a vendor inventory
- Step 2: enable custom-domain DKIM for each vendor
- Step 3: consider a subdomain per vendor
- Step 4: verify with real messages
- Step 5: handle vendors that cannot align
- Offboarding matters as much as onboarding
- Checklist before enforcing DMARC
- Key takeaways
Your own mail servers probably sign correctly. Your CRM, help desk, billing tool, survey platform and event software might not.
Before you move DMARC to enforcement, every vendor that sends as your domain needs to produce a DKIM signature that aligns with it.
Why vendor DKIM so often does not align
By default, many software-as-a-service platforms sign outbound mail with their own domain:
From: Billing <[email protected]>
DKIM-Signature: v=1; a=rsa-sha256; d=vendor-mail.example; s=s1; ...
That signature is valid. It passes DKIM. But DMARC requires the DKIM d= domain to align with the From domain, and vendor-mail.example does not align with example.com. Unless SPF passes and aligns instead, which is unlikely if the vendor uses its own bounce domain, DMARC fails.
While your policy is p=none, this failure only shows up in reports. The moment you move to p=quarantine or p=reject, those invoices and support replies start landing in spam or bouncing.
Step 1: build a vendor inventory
You cannot fix senders you do not know about. Combine three sources:
- DMARC aggregate reports. Every source IP that sent mail with your domain in the From header appears here, with its SPF and DKIM results. Group by the reporting organization and source, and look up who owns unfamiliar IPs.
- Ask the teams. Finance, support, marketing, recruiting, product and sales each tend to have tools that send email. A short survey usually turns up a few surprises.
- Look at your DNS. Existing
include:entries in SPF and CNAMEs under_domainkeyhint at vendors someone set up in the past.
Record for each vendor: what it sends, which From addresses it uses, current SPF and DKIM results, and who owns the account.
| Vendor | Purpose | From address | DKIM d= | Aligned? | Owner |
|---|---|---|---|---|---|
| Help desk | Ticket replies | [email protected] | vendor domain | No | Support lead |
| Billing | Invoices | [email protected] | example.com | Yes | Finance |
| Survey tool | NPS surveys | [email protected] | none | No | Product |
Step 2: enable custom-domain DKIM for each vendor
Almost every reputable sending platform supports signing with your domain. The setting goes by names like "domain authentication," "custom DKIM," "sender authentication" or "branded sending." The usual mechanism is one or more CNAME records you publish:
vd1._domainkey.example.com. CNAME vd1.example-com.dkim.vendor.example.
vd2._domainkey.example.com. CNAME vd2.example-com.dkim.vendor.example.
The CNAME delegates a selector on your domain to a key the vendor hosts and controls. The vendor signs with d=example.com; s=vd1, the receiver follows the CNAME to fetch the public key, and the signature aligns.
CNAME delegation has real advantages: the vendor can rotate keys without asking you, and you never handle their private key. The trade-off is trust. Anyone who controls that CNAME target can sign as your domain, which is exactly why the vendor inventory and periodic review matter.
Some vendors instead give you a TXT record containing the public key. That works too, but rotation then requires your involvement.
Step 3: consider a subdomain per vendor
You do not have to let every vendor sign as your root domain. With relaxed DMARC alignment, a signature with d=help.example.com aligns with a From address at example.com, and a From address at help.example.com aligns too.
Giving higher-risk or high-volume vendors their own subdomain has two benefits:
- Reputation isolation. If a marketing platform's sending practices hurt reputation, the damage is concentrated on that subdomain rather than your primary domain.
- Cleaner revocation. Offboarding a vendor means removing records under one subdomain.
The downside is that recipients see a different From domain, which may or may not matter for your brand. For support or billing mail, many teams prefer the root domain; for surveys and marketing, subdomains are common.
Step 4: verify with real messages
For each vendor, trigger a real message to a mailbox you control and read Authentication-Results:
Authentication-Results: mx.receiver.example;
dkim=pass header.d=example.com header.s=vd1;
spf=pass smtp.mailfrom=bounces.vendor.example;
dmarc=pass header.from=example.com
Here SPF passes but does not align (the envelope domain belongs to the vendor), while DKIM passes and aligns. DMARC passes on DKIM alone. That is a perfectly healthy result.
Then watch the next few days of DMARC aggregate reports to confirm the vendor's traffic now shows aligned DKIM passes across receivers, not just in your test.
Step 5: handle vendors that cannot align
Occasionally a vendor offers no custom-domain DKIM at all. Your options:
- Use a different From domain. Let the vendor send from its own domain or from a subdomain you set aside for it, so its unaligned mail is not judged against your enforced policy. A subdomain still needs its own DMARC handling; the
sp=tag on your root record, or a separate record on the subdomain, controls that. - Route through your own infrastructure. Some tools can send through an SMTP relay you control, which then signs with your key.
- Replace the vendor. If a tool cannot authenticate mail as your domain in this decade, that is useful information for your next procurement review.
Offboarding matters as much as onboarding
When you stop using a vendor, remove its DKIM CNAMEs and SPF include. A forgotten CNAME means a former vendor, or whoever later controls that hostname, can still sign mail that passes DMARC for your domain.
Checklist before enforcing DMARC
- Every vendor sending as your domain is in the inventory with an owner.
- Each vendor signs with
d=equal to your domain or one of its subdomains. - Real test messages show
dkim=passwith an aligned domain. - DMARC reports show aligned passes for each vendor across multiple receivers.
- Vendors that cannot align have been moved off your domain.
- Offboarded vendors' DNS records have been removed.
Key takeaways
- Vendor DKIM often passes but does not align, which only becomes visible when you enforce DMARC.
- DMARC reports plus a team survey give you a complete vendor inventory.
- CNAME-delegated selectors let vendors sign as your domain and rotate keys themselves.
- Subdomains per vendor isolate reputation and simplify offboarding.
- Remove DNS records for vendors you no longer use.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


