DMARC (Domain-Based Message Authentication, Reporting, and Conformance)
Definition
A policy layer that requires the domain in the visible From header to align with a domain that passes SPF or DKIM. A DMARC fail means neither SPF nor DKIM produced a passing result aligned with the From domain, which is strong evidence of spoofing.
- Full name
- Domain-based Message Authentication, Reporting, and Conformance
- Requires
- From-header domain alignment with SPF or DKIM pass
- DMARC fail meaning
- Neither SPF nor DKIM aligned with the From domain
- Evidentiary value
- Strong indicator of spoofing
Common questions
Can a message pass SPF but still fail DMARC?+
Yes, SPF can pass for the envelope-sender domain while the visible From header shows a different domain; DMARC requires alignment between the two, so a mismatch fails DMARC even with a passing SPF check.
Why do investigators treat a DMARC fail as strong rather than conclusive evidence of spoofing?+
Misconfiguration, legitimate third-party senders, or mailing-list forwarding can also produce a DMARC fail, so the result is corroborated with header path analysis and other indicators rather than treated as proof on its own.
Related terms
- DKIM (DomainKeys Identified Mail)
- A cryptographic signing mechanism: the sending server signs the message headers and body with a private key, and the receiving server verifies...
- Envelope Sender (Return-Path)
- The address used at the SMTP protocol level for bounce notifications, recorded in the Return-Path header. It is distinct from the display...
- Message-ID
- A globally unique identifier assigned to each message by the originating mail server, recorded in the Message-ID header. It is set by...
- Received Header
- A header line prepended by each mail server that accepts a message in transit, recording the server's own identity, the IP or...
- SPF (Sender Policy Framework)
- A DNS-based mechanism by which a domain owner publishes the list of IP addresses authorised to send mail for that domain. A...