Relaxed vs strict DMARC alignment: choosing adkim and aspf
Relaxed alignment accepts subdomains, strict demands an exact match. See how each mode evaluates real headers and when strict is worth the risk.

On this page(11 sections)
- Alignment in one paragraph
- The two modes
- Relaxed
- Strict
- Worked examples
- How the organizational domain is determined
- Why relaxed is usually right
- When strict alignment makes sense
- Untrusted subdomains
- Highly sensitive From domains
- Strict on one mechanism only
- The risk of going strict
- Checking alignment on a real message
- Alignment and the bounce path
- A decision checklist
- Bottom line
DMARC does not ask whether SPF or DKIM passed. It asks whether they passed for a domain that matches the one in the From header.
How closely those domains must match is controlled by two small tags, adkim and aspf, and the default is right for almost everyone.
Alignment in one paragraph
A message has several domain identities: the visible From header, the envelope sender checked by SPF, and the d= domain in each DKIM signature. DMARC passes only when SPF or DKIM passes and the authenticated domain aligns with the From domain. Alignment is what stops an attacker from passing SPF for their own domain while putting yours in the From line.
The two modes
Each mechanism has its own alignment mode:
adkimcontrols DKIM alignment.aspfcontrols SPF alignment.
Each can be r (relaxed, the default) or s (strict).
_dmarc.example.com. TXT "v=DMARC1; p=reject; adkim=r; aspf=r; rua=mailto:[email protected]"
Relaxed
The authenticated domain and the From domain must share the same organizational domain. In practice that means one can be a subdomain of the other, or both can be subdomains of the same parent.
Strict
The authenticated domain must be exactly the From domain. No subdomains, no parents.
Worked examples
Assume the From header is [email protected].
| Authenticated domain | Relaxed | Strict |
|---|---|---|
DKIM d=example.com |
Aligned | Aligned |
DKIM d=mail.example.com |
Aligned | Not aligned |
SPF MAIL FROM at bounce.example.com |
Aligned | Not aligned |
DKIM d=example.net |
Not aligned | Not aligned |
SPF MAIL FROM at vendor-mail.example |
Not aligned | Not aligned |
Now assume the From header is [email protected].
| Authenticated domain | Relaxed | Strict |
|---|---|---|
DKIM d=example.com |
Aligned | Not aligned |
DKIM d=app.example.com |
Aligned | Aligned |
SPF at bounce.example.com |
Aligned | Not aligned |
The relaxed rule is symmetric: a parent domain aligns with a subdomain and vice versa, as long as both share the same organizational domain.
How the organizational domain is determined
"Same organizational domain" sounds simple for example.com, but not for names like example.co.uk, where co.uk is a public suffix. Under the original DMARC specification, receivers used the Public Suffix List to decide. RFC 9989, published in 2026, replaces that with a DNS tree walk over _dmarc records. For typical company domains the result is identical; the distinction matters mainly for unusual registry structures.
Why relaxed is usually right
Relaxed alignment supports the patterns that make email infrastructure manageable:
- Custom bounce subdomains. Sending providers often use
bounce.example.comas the envelope sender so bounces route back to them. Relaxed SPF alignment lets that pass for a From address atexample.com. - Subdomain DKIM signing. Some vendors sign with
d=em.example.comor similar. Relaxed DKIM alignment accepts it. - Stream separation. You can put marketing on
news.example.comand still sign with the parent domain, or the reverse.
With strict alignment, each of those setups fails DMARC unless every identity uses exactly the From domain.
When strict alignment makes sense
Strict alignment buys you something in a narrow set of situations:
Untrusted subdomains
If parts of your domain tree are delegated to other parties, such as a customer-facing subdomain run by a hosting provider, or a university department with its own mail server, relaxed alignment means mail authenticated by those subdomains can pass DMARC for your parent domain's From addresses. Strict alignment prevents that.
Highly sensitive From domains
A domain used only for a few high-value messages, such as security alerts, with a short, fully controlled sender list, can use strict alignment to rule out any subdomain-based abuse.
Strict on one mechanism only
Modes are independent. A reasonable pattern for some organizations is strict SPF with relaxed DKIM:
v=DMARC1; p=reject; adkim=r; aspf=s; rua=mailto:[email protected]
SPF identities tend to be the noisier of the two, since many vendors use their own bounce domains anyway, while DKIM keys are under tighter control.
The risk of going strict
Strict alignment frequently breaks legitimate mail that nobody remembered depended on relaxed alignment:
- A vendor that signs with
d=em.example.comstops passing. - Bounce subdomains stop providing an aligned SPF pass, so DMARC relies entirely on DKIM.
- Mail that previously had two aligned paths now has one, so any DKIM failure becomes a DMARC failure.
If you switch, do it while watching aggregate reports, ideally first at p=none or with a subdomain policy, so you can see which sources lose alignment before enforcement makes it painful.
Checking alignment on a real message
Read the Authentication-Results header on a received message:
Authentication-Results: mx.receiver.example;
spf=pass smtp.mailfrom=bounce.example.com;
dkim=pass header.d=example.com header.s=k1;
dmarc=pass (p=reject) header.from=example.com
Compare smtp.mailfrom and header.d with header.from. Under relaxed alignment both of these align. Under strict SPF alignment, only DKIM would.
Alignment and the bounce path
One practical detail often gets missed when teams discuss SPF alignment: the envelope sender is also where bounces go. Providers that use their own bounce domain do so because they need to receive and process delivery failures for you. If you insist on strict SPF alignment, you are effectively asking every provider to use your exact From domain as the envelope sender, which means bounces arrive at your domain and the provider loses visibility into them unless you forward them back.
That is one more reason relaxed SPF alignment, combined with a custom bounce subdomain that points back to the provider, is the standard pattern. It keeps bounce handling with the system that sent the message while still giving DMARC an aligned SPF pass. Strict DKIM alignment does not have this side effect, because DKIM has nothing to do with bounce routing.
A decision checklist
- Do any vendors sign with a subdomain or use a subdomain bounce domain? Stay relaxed for that mechanism.
- Is any part of your domain tree operated by someone else? Consider strict.
- Is this a narrow, high-value From domain with a tiny sender list? Strict may be worth it.
- Have you reviewed at least two weeks of aggregate reports with the proposed mode in mind? If not, do that first.
Bottom line
Alignment is the heart of DMARC, and relaxed mode, the default, is the right choice for most domains because it supports bounce subdomains and subdomain signing. Strict alignment helps when subdomains are controlled by other parties or for narrow, sensitive From domains. Whatever you choose, check aggregate reports before and after the change.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

