DMARC Strict vs Relaxed Alignment: Which Should You Use?
Relaxed alignment is the right choice for nearly every sender. DMARC's adkim=r and aspf=r tags (the defaults when you omit them) allow subdomains to align with the From domain — so news.example.com aligns with user@example.com. Strict alignment (adkim=s, aspf=s) demands an exact match and breaks the moment any legitimate sender uses a subdomain. Most ESPs, marketing platforms, and internal mail systems do exactly that.
Here's what each mode does, when strict makes sense, and how to set it correctly.
What the adkim and aspf Tags Control
Your DMARC record lives in DNS as a TXT record at _dmarc.yourdomain.com. Two optional tags control alignment strictness:
_dmarc.yourdomain.com. TXT "v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc@yourdomain.com"
| Tag | Controls | Values |
|---|---|---|
adkim= |
DKIM alignment mode | r (relaxed, default) or s (strict) |
aspf= |
SPF alignment mode | r (relaxed, default) or s (strict) |
If you omit both tags — which most DMARC records do — relaxed is applied for both. That's the right starting point.
DKIM alignment compares the d= domain in the DKIM signature to the domain in the From: header. SPF alignment compares the envelope return-path domain (the hidden bounce address) to the From: domain. The adkim and aspf tags control how strict that comparison is — not whether authentication itself runs.
Relaxed Alignment: Subdomain Matching
Under relaxed mode, DMARC compares the organizational domain (the registered domain plus one level of TLD) rather than the exact hostname. This means a subdomain of your From domain — or your From domain being a subdomain of the authenticated domain — still passes alignment.
Concretely, if your From address is user@example.com:
| Authenticated domain | Relaxed | Strict |
|---|---|---|
example.com |
✅ aligns | ✅ aligns |
mail.example.com |
✅ aligns | ❌ fails |
news.example.com |
✅ aligns | ❌ fails |
sendgrid.net |
❌ fails | ❌ fails |
example.co.uk |
❌ fails (different org domain) | ❌ fails |
The last row is important: relaxed does NOT mean "anything goes." It means subdomains of the same organizational domain align. A completely different domain like sendgrid.net never aligns with example.com under either mode.
Why relaxed is the default
Most real-world email infrastructure involves subdomains:
- ESP return-paths. SendGrid, Mailgun, and Amazon SES often set the envelope return-path to a subdomain like
bounce@example.comvia their SPF, or to their own domain entirely. If your ESP uses a subdomain of your domain for the return-path, relaxed SPF alignment passes where strict would fail. - DKIM signing selectors. Your DKIM signature's
d=tag might be set toyourdomain.comby your ESP, but some configurations sign withmail.yourdomain.com— especially when you delegate a subdomain to your ESP for sending. - Internal mail servers. Many organizations have
mail.yourdomain.comorsmtp.yourdomain.comas their outgoing server. If that server's DKIM signature uses the subdomain asd=, strict alignment fails.
Relaxed mode handles all of these without configuration changes. Strict mode requires that every single sending source — marketing, transactional, internal, CRM, billing — signs and sends from the exact bare domain.
Strict Alignment: Exact Match Only
Strict alignment (adkim=s or aspf=s) requires the authenticated domain to be a byte-for-byte match with the From domain. No subdomain tolerance.
_dmarc.yourdomain.com. TXT "v=DMARC1; p=reject; adkim=s; aspf=s; rua=mailto:dmarc@yourdomain.com"
Under strict mode, if your From address is user@yourdomain.com:
- DKIM
d=yourdomain.com→ aligns ✅ - DKIM
d=mail.yourdomain.com→ fails ❌ - SPF return-path
yourdomain.com→ aligns ✅ - SPF return-path
bounce.yourdomain.com→ fails ❌
When strict alignment makes sense
Strict is worth considering only when ALL of these are true:
- You have complete visibility into every sending source. Every server, ESP, SaaS tool, and automated system that sends mail as your domain — you know about it and control its DKIM/SPF configuration.
- No sending source uses a subdomain. Every DKIM signature uses
d=yourdomain.com(notd=mail.yourdomain.com), and every return-path usesyourdomain.com(not a subdomain). - You have a security requirement for maximum spoofing resistance. Strict alignment makes it harder for an attacker who controls a subdomain to spoof the parent domain — though this is a narrow attack surface, since subdomain compromise already implies significant access.
In practice, these conditions are met almost exclusively by small organizations that send all mail through a single provider configured to sign with the bare domain. If you use more than one ESP, send marketing and transactional mail through different platforms, or have internal servers that handle mail, strict will cause legitimate mail to fail DMARC.
The risk of switching to strict
If you set aspf=s and your ESP's return-path uses a subdomain, SPF alignment fails for every message through that ESP. DMARC then falls back to DKIM alignment alone. If DKIM also fails — because the ESP doesn't sign with your domain, or the signature breaks in transit — DMARC fails, and your p=quarantine or p=reject policy acts on your own legitimate mail.
This is the most common cause of self-inflicted email delivery failures after a DMARC rollout. The fix is simple: switch back to relaxed, or ensure every sending source uses the bare domain for both DKIM signing and return-path.
How to Check Which Mode You're Using
Look at your DMARC TXT record in DNS:
dig TXT _dmarc.yourdomain.com
Or use nslookup:
nslookup -type=TXT _dmarc.yourdomain.com
Check for the adkim= and aspf= tags in the response:
- No
adkim=oraspf=tags → relaxed for both (default) adkim=r→ relaxed DKIM alignmentadkim=s→ strict DKIM alignmentaspf=r→ relaxed SPF alignmentaspf=s→ strict SPF alignment
You can also run a free DMARC scan — it reads your live DNS records and tells you whether alignment is configured, which mode is active, and whether anything is misconfigured.
Can You Mix Modes?
Yes. adkim and aspf are independent. Common configurations:
Relaxed for both (recommended):
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com
(Omitting both tags defaults to relaxed/relaxed.)
Strict DKIM, relaxed SPF:
v=DMARC1; p=quarantine; adkim=s; rua=mailto:dmarc@yourdomain.com
Useful if your DKIM signing always uses the bare domain but your return-path sometimes uses a subdomain.
Strict for both (rare):
v=DMARC1; p=reject; adkim=s; aspf=s; rua=mailto:dmarc@yourdomain.com
Only when you have full control over every sending source and none use subdomains.
The Practical Recommendation
Start with relaxed (the default). Monitor your DMARC aggregate reports for a few weeks. If every legitimate source is authenticating and aligning cleanly with the bare domain — no subdomain involvement anywhere — you can consider switching to strict. But there is no urgency: relaxed alignment still prevents spoofing from external domains, which is the primary threat DMARC addresses.
The more common problem is the opposite: senders who unknowingly have strict alignment enabled (often inherited from a template or copied record) and can't figure out why their legitimate mail fails DMARC. If your reports show alignment failures on mail you know you sent, check your adkim and aspf tags first.
Check your grade free
Don't guess what's broken — see it. Scan your domain free at emailsecuritygrade.com and get an instant A–F grade on your SPF, DKIM, DMARC, and MX records, with a plain-language fix for anything failing. No signup, no install — it runs in your browser.
If your emails are still landing in spam after fixing the records, a deliverability tool like InboxAlly can train mailbox providers to trust your sending — worth a look once your grade is solid.
Correcting SPF, DKIM, and DMARC is step one — but inbox providers don't trust a domain overnight. InboxAlly trains Gmail, Outlook, and Yahoo to trust your sending domain by generating real engagement signals, so your emails stop landing in spam within weeks instead of months. Most users see open rates double in 2–4 weeks.
Start free with InboxAlly →