communication email_delivery ai_generated true

Emails sent via API land in spam despite valid SPF and DKIM because of alignment failure

ID: communication/email-spf-dkim-alignment-spam

Also available as: JSON · Markdown
85%Fix Rate
90%Confidence
3Evidence
2023-01-01First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
any active

Root Cause

DMARC requires 'alignment': the domain in SPF/DKIM must match the From header domain. Sending from [email protected] via SendGrid (SPF passes for sendgrid.net, not example.com) fails DMARC alignment even though SPF itself passes.

generic

Workarounds

  1. 95% success Configure custom DKIM signing with your domain on the email service provider
    Add CNAME records for DKIM: selector._domainkey.example.com -> service-provided-value. This makes DKIM align with your From domain.
  2. 90% success Set up custom Return-Path domain for SPF alignment
    Configure bounce subdomain: bounces.example.com CNAME to service's domain. Envelope sender aligns with From domain.
  3. 85% success Start with DMARC p=none to monitor before enforcing
    v=DMARC1; p=none; rua=mailto:[email protected]  # monitor alignment failures before setting p=reject

Dead Ends

Common approaches that don't work:

  1. Set up SPF and DKIM and assume emails won't be marked as spam 88% fail

    SPF and DKIM can both pass independently but DMARC still fails if neither aligns with the From domain. SPF must pass for the From domain, not just the envelope sender.

  2. Use email service provider's default sending domain 85% fail

    Sending from [email protected] via service's domain means SPF passes for the service domain, not yours. DMARC alignment fails.