Skip to content

Is relaxed DKIM alignment actually a problem?

A DMARC record containing adkim=r is not automatically broken. Alignment mode is a policy choice. Check real messages and your subdomain controls before changing it to adkim=s.

Authentication and alignment are separate checks

A valid DKIM signature authenticates a signing domain. DMARC also evaluates its alignment with the domain in the visible From address. Relaxed alignment compares organizational domains; strict alignment requires the domains to be identical. The choice is not the same as DMARC enforcement policy: p=none, quarantine and reject address a different question.

Compare the domains in a real message

Send a representative message through each system the business actually uses: staff email, invoices, website forms and campaigns. Inspect the received message headers and record its visible From domain, DKIM signing domain and receiver authentication results. Treat this as a sender inventory rather than assuming your staff mailbox represents every service.

Visible From domain: example.com
Validated DKIM d= domain: mail.example.com
Relaxed alignment: aligned
Strict alignment: not aligned
  1. Record each sending service and its owner.
  2. Check a delivered sample, not only the provider dashboard.
  3. Distinguish a valid signature from whether its domain aligns.
  4. Include uncommon senders, such as password resets and billing systems.

When strict alignment may be appropriate

Consider strict alignment where exact-domain control is required and all intended sending paths support it. Review delegated subdomains and who can operate them. Relaxed alignment does not let anyone forge a valid signature; a real risk can arise from control over an aligned subdomain. The current DMARC standard leaves the choice to the domain owner and notes that relaxed alignment is sufficient for many deployments. Do not make a DNS change just to remove a warning.

Test before changing production email policy

Ask the email administrator to show which sending paths would still authenticate and align under the proposed configuration. Where a provider cannot sign with the required domain, repair its configuration or choose a policy compatible with the intended sender. Keep the existing record, schedule the change, and define the legitimate-mail checks and rollback condition before publishing.

  1. Review observed DMARC results for each legitimate service.
  2. Identify any sender that relies on a different aligned subdomain.
  3. Agree the intended DKIM and SPF alignment modes with the domain owner.
  4. After a change, retest those senders and investigate legitimate failures promptly.

What the website finding can establish

A public DNS observation can show the published alignment mode. It cannot prove that all business mail passes, that every receiver uses the same implementation, or that a change is safe. For a useful handover, include the observed DNS record, representative sender results, subdomain ownership and the administrator decision. Do not share full message headers publicly without removing personal addresses and other private details.

Frequently asked questions

Is adkim=r insecure by default?

No. It is a valid relaxed alignment policy. Review sender requirements and subdomain control to decide whether stricter matching is appropriate.

Does adkim=s replace p=reject?

No. Alignment mode and the requested handling of DMARC failures are separate settings.

Can I change adkim without testing?

That can disrupt legitimate sending paths. Inventory and test the services that send as the business before publishing a stricter mode.

See where your website stands

Start with a public-signal screening report in about 60 seconds. No signup or card. Quick Scan samples the website; it does not test every topic in this guide.

Run a free scan