DMARC Analyzer

DKIM alignment: signing domain vs header_from

The domain DKIM actually authenticates is the signature's d= tag, which is chosen by whoever configured signing and is not required to match anything else in the message. DMARC then checks whether d= aligns with header_from, per the adkim mode. A message can be legitimately signed by a third-party sending platform (d=platform.example) while claiming From: you@yourdomain.com โ€” DKIM passes, but alignment fails, unless that platform signs with your domain instead.

References