SPF alignment: MAIL FROM vs header_from
← All help articles · SPF
SPF's pass/fail decision is about the SMTP envelope sender (MAIL FROM, sometimes called the "bounce address" or Return-Path) — a technical address the recipient usually never sees, and which forwarders/mailing lists commonly rewrite to their own domain. DMARC then separately checks whether that authenticated domain aligns with the visible header_from domain, per the aspf mode.
This is exactly why forwarded mail often fails DMARC on the SPF path even when the original sender was legitimate — the forwarder's MAIL FROM doesn't align with the original header_from. This tool's R12 recommendation recognizes that pattern for known forwarders and explicitly advises no action.
References
- RFC 7208 §2.4