emailsecuritygrade.com

DMARC Strict vs Relaxed Alignment: Which Should You Use?

September 24, 2026

Relaxed alignment is the right choice for nearly every sender. DMARC's adkim=r and aspf=r tags (the defaults when you omit them) allow subdomains to align with the From domain — so news.example.com aligns with user@example.com. Strict alignment (adkim=s, aspf=s) demands an exact match and breaks the moment any legitimate sender uses a subdomain. Most ESPs, marketing platforms, and internal mail systems do exactly that.

Here's what each mode does, when strict makes sense, and how to set it correctly.

What the adkim and aspf Tags Control

Your DMARC record lives in DNS as a TXT record at _dmarc.yourdomain.com. Two optional tags control alignment strictness:

_dmarc.yourdomain.com.  TXT  "v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc@yourdomain.com"
Tag Controls Values
adkim= DKIM alignment mode r (relaxed, default) or s (strict)
aspf= SPF alignment mode r (relaxed, default) or s (strict)

If you omit both tags — which most DMARC records do — relaxed is applied for both. That's the right starting point.

DKIM alignment compares the d= domain in the DKIM signature to the domain in the From: header. SPF alignment compares the envelope return-path domain (the hidden bounce address) to the From: domain. The adkim and aspf tags control how strict that comparison is — not whether authentication itself runs.

Relaxed Alignment: Subdomain Matching

Under relaxed mode, DMARC compares the organizational domain (the registered domain plus one level of TLD) rather than the exact hostname. This means a subdomain of your From domain — or your From domain being a subdomain of the authenticated domain — still passes alignment.

Concretely, if your From address is user@example.com:

Authenticated domain Relaxed Strict
example.com ✅ aligns ✅ aligns
mail.example.com ✅ aligns ❌ fails
news.example.com ✅ aligns ❌ fails
sendgrid.net ❌ fails ❌ fails
example.co.uk ❌ fails (different org domain) ❌ fails

The last row is important: relaxed does NOT mean "anything goes." It means subdomains of the same organizational domain align. A completely different domain like sendgrid.net never aligns with example.com under either mode.

Why relaxed is the default

Most real-world email infrastructure involves subdomains:

  • ESP return-paths. SendGrid, Mailgun, and Amazon SES often set the envelope return-path to a subdomain like bounce@example.com via their SPF, or to their own domain entirely. If your ESP uses a subdomain of your domain for the return-path, relaxed SPF alignment passes where strict would fail.
  • DKIM signing selectors. Your DKIM signature's d= tag might be set to yourdomain.com by your ESP, but some configurations sign with mail.yourdomain.com — especially when you delegate a subdomain to your ESP for sending.
  • Internal mail servers. Many organizations have mail.yourdomain.com or smtp.yourdomain.com as their outgoing server. If that server's DKIM signature uses the subdomain as d=, strict alignment fails.

Relaxed mode handles all of these without configuration changes. Strict mode requires that every single sending source — marketing, transactional, internal, CRM, billing — signs and sends from the exact bare domain.

Strict Alignment: Exact Match Only

Strict alignment (adkim=s or aspf=s) requires the authenticated domain to be a byte-for-byte match with the From domain. No subdomain tolerance.

_dmarc.yourdomain.com.  TXT  "v=DMARC1; p=reject; adkim=s; aspf=s; rua=mailto:dmarc@yourdomain.com"

Under strict mode, if your From address is user@yourdomain.com:

  • DKIM d=yourdomain.com → aligns ✅
  • DKIM d=mail.yourdomain.com → fails ❌
  • SPF return-path yourdomain.com → aligns ✅
  • SPF return-path bounce.yourdomain.com → fails ❌

When strict alignment makes sense

Strict is worth considering only when ALL of these are true:

  1. You have complete visibility into every sending source. Every server, ESP, SaaS tool, and automated system that sends mail as your domain — you know about it and control its DKIM/SPF configuration.
  2. No sending source uses a subdomain. Every DKIM signature uses d=yourdomain.com (not d=mail.yourdomain.com), and every return-path uses yourdomain.com (not a subdomain).
  3. You have a security requirement for maximum spoofing resistance. Strict alignment makes it harder for an attacker who controls a subdomain to spoof the parent domain — though this is a narrow attack surface, since subdomain compromise already implies significant access.

In practice, these conditions are met almost exclusively by small organizations that send all mail through a single provider configured to sign with the bare domain. If you use more than one ESP, send marketing and transactional mail through different platforms, or have internal servers that handle mail, strict will cause legitimate mail to fail DMARC.

The risk of switching to strict

If you set aspf=s and your ESP's return-path uses a subdomain, SPF alignment fails for every message through that ESP. DMARC then falls back to DKIM alignment alone. If DKIM also fails — because the ESP doesn't sign with your domain, or the signature breaks in transit — DMARC fails, and your p=quarantine or p=reject policy acts on your own legitimate mail.

This is the most common cause of self-inflicted email delivery failures after a DMARC rollout. The fix is simple: switch back to relaxed, or ensure every sending source uses the bare domain for both DKIM signing and return-path.

How to Check Which Mode You're Using

Look at your DMARC TXT record in DNS:

dig TXT _dmarc.yourdomain.com

Or use nslookup:

nslookup -type=TXT _dmarc.yourdomain.com

Check for the adkim= and aspf= tags in the response:

  • No adkim= or aspf= tags → relaxed for both (default)
  • adkim=r → relaxed DKIM alignment
  • adkim=s → strict DKIM alignment
  • aspf=r → relaxed SPF alignment
  • aspf=s → strict SPF alignment

You can also run a free DMARC scan — it reads your live DNS records and tells you whether alignment is configured, which mode is active, and whether anything is misconfigured.

Can You Mix Modes?

Yes. adkim and aspf are independent. Common configurations:

Relaxed for both (recommended):

v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com

(Omitting both tags defaults to relaxed/relaxed.)

Strict DKIM, relaxed SPF:

v=DMARC1; p=quarantine; adkim=s; rua=mailto:dmarc@yourdomain.com

Useful if your DKIM signing always uses the bare domain but your return-path sometimes uses a subdomain.

Strict for both (rare):

v=DMARC1; p=reject; adkim=s; aspf=s; rua=mailto:dmarc@yourdomain.com

Only when you have full control over every sending source and none use subdomains.

The Practical Recommendation

Start with relaxed (the default). Monitor your DMARC aggregate reports for a few weeks. If every legitimate source is authenticating and aligning cleanly with the bare domain — no subdomain involvement anywhere — you can consider switching to strict. But there is no urgency: relaxed alignment still prevents spoofing from external domains, which is the primary threat DMARC addresses.

The more common problem is the opposite: senders who unknowingly have strict alignment enabled (often inherited from a template or copied record) and can't figure out why their legitimate mail fails DMARC. If your reports show alignment failures on mail you know you sent, check your adkim and aspf tags first.

Check your grade free

Don't guess what's broken — see it. Scan your domain free at emailsecuritygrade.com and get an instant A–F grade on your SPF, DKIM, DMARC, and MX records, with a plain-language fix for anything failing. No signup, no install — it runs in your browser.

If your emails are still landing in spam after fixing the records, a deliverability tool like InboxAlly can train mailbox providers to trust your sending — worth a look once your grade is solid.

Fixed your records? Now fix deliverability.

Correcting SPF, DKIM, and DMARC is step one — but inbox providers don't trust a domain overnight. InboxAlly trains Gmail, Outlook, and Yahoo to trust your sending domain by generating real engagement signals, so your emails stop landing in spam within weeks instead of months. Most users see open rates double in 2–4 weeks.

Start free with InboxAlly →