DMARC depends on alignment
DMARC works by checking that the domain you see in the From line matches the domain that passed authentication.
That matching is the whole mechanism. A message can pass the underlying checks and still fail DMARC because the authenticated domain belongs to somebody else, which is precisely the spoofing case it exists to catch. Configuring the checks without alignment produces passes that mean nothing.
More on Email security
- DKIM protects signed content against later modificationChange one word, break the seal
- Forwarding can break email authentication assumptionsIt was re-posted on the way
- A display name is not an email addressThey wrote that name themselves
- Reply-chain hijacking borrows existing trustTrust borrowed from the thread
- Secure email gateways see only traffic that reaches themIt only sees what comes past it
- Quarantine creates a second security decisionHeld is not decided
