One Email, Three Identities: Why SPF, DKIM, and DMARC Don't Check the Same Thing

One Email, Three Identities: SPF, DKIM and DMARC Explained

A single email carries three separate domain identities—the visible From, the envelope sender, and the DKIM signing domain—plus the sending IP, and nothing requires them to match. This article explains how SPF, DKIM, and DMARC each check different identities, using a realistic example of an invoice sent through an ESP. It shows how a message can pass DMARC even when SPF doesn't align, and how a common ESP misconfiguration (using the ESP's default DKIM domain) causes legitimate mail to fail DMARC. The piece also covers relaxed vs. strict alignment and how to diagnose alignment issues using DMARC aggregate reports.

It looks identical from the mail client's side, a legitimate email, sent through a paid-for legitimate provider, landing in spam or getting rejected. The difference is entirely in `d=`, a field the sender's marketing team never sees and has no reason to know exists.

More from this day

2026-08-10