What "alignment" means
← All help articles · DMARC fundamentals
SPF and DKIM each authenticate a domain, but not necessarily the one shown in the visible From: header a recipient sees. SPF authenticates the envelope MAIL FROM domain; DKIM authenticates whatever domain signed the message (d=). DMARC requires at least one of those to also align — match (exactly or by organizational domain, per adkim/aspf) — with header_from.
This is why a message can show spf=pass and dkim=pass in a raw report and still fail DMARC overall: both mechanisms authenticated a real domain, just not the one in From:. This tool's R3 recommendation specifically flags known senders whose auth mechanism passed but alignment didn't.
References
- RFC 7489 §3.1