adkim= — DKIM alignment mode
← All help articles · DMARC fundamentals
adkim=r (relaxed, the default) accepts DKIM alignment as long as the signing domain (d= in the DKIM-Signature header) shares the same organizational/registrable domain as header_from — e.g. mail.example.com aligns with example.com. adkim=s (strict) requires the two to match exactly.
Relaxed mode is almost always the right default; strict mode is a rarely-needed hardening step that will break legitimate mail from subdomains you haven't accounted for.
References
- RFC 7489 §6.3