How Does a DMARC Check Work? A Step-by-Step Guide to DMARC Validation

Reviewed by Ali Aleali, CISSP, CCSP · Last reviewed September 30, 2026

A DMARC check looks at a message that has already gone through SPF and DKIM, and asks one more question: does the domain that passed either of those checks match the domain a recipient sees in the From address? If it does, DMARC passes. If it does not, the receiving server applies the policy the domain owner published in DNS, which tells it whether to deliver the message anyway, treat it as suspicious, or refuse it outright. DMARC verification is what turns two separate authentication results into one decision about spoofing.

What Information Does a DMARC Check Use?

A DMARC check pulls together results from earlier in the process rather than testing anything new on its own:

  • The visible From domain, the domain a recipient sees in their inbox. This is the identity DMARC protects.
  • The domain's DMARC record, a DNS TXT record published at _dmarc.domain, which states the policy and where to send reports.
  • The SPF result and its authenticated domain, carried over from the SPF check described in the companion post on how an SPF check works.
  • The DKIM result and its authenticated d= domain, carried over from the DKIM check described in the companion post on how a DKIM check works.
  • The alignment mode, set by the adkim= and aspf= tags, which decides how closely an authenticated domain must match the From domain.
  • The policy, set by the p= tag, which tells the receiver what to do when nothing aligns.

DMARC Verification Process

Diagram showing the eight steps of how a DMARC check works: identifying the From domain, looking up the DMARC record, checking SPF and DKIM results and alignment, and applying the published policy.

The sequence above brings SPF and DKIM together into a single alignment check.

  1. The receiving server receives the message and identifies the visible From domain.
  2. It retrieves the domain's DMARC record from DNS.
  3. It checks the message's SPF authentication result.
  4. It checks whether the SPF-authenticated domain aligns with the visible From domain.
  5. It checks the message's DKIM signature result.
  6. It checks whether a valid DKIM d= domain aligns with the visible From domain.
  7. DMARC passes if either SPF or DKIM passes and aligns; both are not required.
  8. If DMARC fails, the receiver weighs the published policy against its own local filtering rules, then records the result, which may also feed into an aggregate report sent back to the domain owner.

Steps 3 and 4 check SPF's alignment; steps 5 and 6 check DKIM's alignment independently of SPF. A message only needs one of those two paths to succeed for DMARC to pass, which is why a forwarded message that fails SPF can still pass DMARC on a DKIM signature that survived the trip.

What Do the DMARC Policies Mean?

The p= tag is the part of a DMARC record that tells a receiver what to do with mail that fails alignment.

Policy What it means What receivers do
p=none Monitor only; no enforcement requested Deliver the message normally and send reports if requested
p=quarantine Treat failing mail as suspicious Typically route the message to spam or flag it for review
p=reject Refuse failing mail outright Typically refuse the message during the SMTP transaction, before it reaches a mailbox

These are requested handling instructions, not guarantees. A receiving system can apply its own local policy on top of what a domain publishes, so a p=reject record reduces the risk of a spoofed message reaching an inbox without making it impossible everywhere.

How Does DMARC Alignment Work?

Alignment is the actual comparison between an authenticated domain and the visible From domain, and it comes in two modes. Relaxed alignment, the default, passes as long as the authenticated domain and the From domain share the same organizational domain: DKIM signed as mail.example.com aligns with a From address at example.com. Strict alignment requires an exact match, so mail.example.com would not align with example.com under strict rules.

Most domains run relaxed alignment, since third-party services such as marketing platforms or help desks often sign or send from a subdomain of the organizational domain. Strict alignment is a tightening step for domains that control every system sending in their name.

What Does DMARC Reporting Show?

A DMARC record can include a rua= tag with one or more email addresses, and receiving providers use it to send aggregate reports, typically daily, summarizing every source that sent mail using the domain and whether each one passed aligned SPF or DKIM. Reading those reports is how a domain owner finds sending sources they did not know about before tightening the policy.

Why Do Legitimate Emails Fail DMARC?

Legitimate mail fails DMARC more often from misconfiguration than from anything malicious:

  • A third-party sender uses its own envelope domain, which fails SPF alignment unless the same sender also signs with DKIM on the organizational domain.
  • A platform signs with its own domain in d= instead of the customer's, so DKIM passes for the platform but never aligns for the customer.
  • A legitimate service was never added to SPF or DKIM at all, so it has nothing to align.
  • Forwarding strips SPF while the DKIM signature also breaks if the forwarder modifies the message.
  • Strict alignment is set before every sender is confirmed, turning subdomain-based signing that used to pass under relaxed mode into a failure.

The companion article on how SPF, DKIM and DMARC work together covers how to inventory senders and roll a policy forward without breaking legitimate mail.

See whether your own DMARC record aligns

Truvo verifies SPF, DKIM and DMARC configuration as part of an effective security program, then hands over the evidence.

Frequently Asked Questions

Does DMARC require both SPF and DKIM to pass?

No. DMARC passes when either SPF or DKIM passes and aligns with the visible From domain. Both are not required, which is why DKIM alone can carry a forwarded message through even after SPF fails.

What is the difference between DMARC quarantine and reject?

Quarantine asks receivers to treat failing mail as suspicious, usually by routing it to spam. Reject asks them to refuse it outright, typically before it reaches a mailbox. Both are requests; a receiver can still apply its own local policy.

Does p=reject guarantee that spoofed mail is always blocked?

No. It is the strongest of the three policies and meaningfully reduces the risk, but receivers decide how to apply local policy on top of what a domain publishes.

What is DMARC alignment?

Alignment is the check that compares the domain authenticated by SPF or DKIM against the domain visible in the From address. Relaxed alignment allows a shared organizational domain; strict alignment requires an exact match.

Key Takeaway

A DMARC check does not authenticate a message on its own; it takes the SPF and DKIM results that already exist and asks whether either one aligns with the domain a recipient sees. When one does, DMARC passes. When neither does, the published policy, none, quarantine, or reject, tells the receiver what to do next, though every receiver still applies some of its own judgment on top. Built on accurate SPF and DKIM coverage and reviewed through its own reports, DMARC becomes the piece that ties a domain's email authentication together.

Ready to Start Your Compliance Journey?

Get a clear, actionable roadmap with our readiness assessment.

Contact Us

Share this article:

Sample SOC 2 Control List

Input your email to download the list.

About the Author

Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.