What this check looks at
Every message has two "from" identities: the envelope sender (MAIL FROM, used for bounces and checked by SPF) and the header From (the address your recipient sees). This check compares their domains and, where they differ, leans on the DMARC alignment results captured during the session to decide whether the difference is harmless or a problem.
Why it matters
SPF and DKIM can both pass against a domain that isn't the one in the From header - which is exactly how a spoofer would try to borrow your brand. DMARC closes that gap by requiring alignment: the passing mechanism must be on (or a subdomain of) the From domain. If nothing aligns, DMARC fails no matter how green SPF and DKIM look on their own.
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| Sender alignment | Pass | Envelope and From domains match (or one is a subdomain of the other). |
| Nothing aligns with the From domain | Warning | Neither SPF nor DKIM aligns - DMARC has nothing to pass on. |
| Envelope and From domains differ | Info | Common with sending providers. Fine as long as DKIM is signed by the From domain. |
| Alignment couldn't be compared | Info | One of the two domains wasn't available on this message. |
How to fix it
You don't need the envelope and From domains to be identical - you need at least one aligned, passing mechanism:
- Best: sign with a DKIM key published on your From domain. DKIM alignment survives forwarding, so this is the most robust fix.
- Or: use a bounce /
MAIL FROMaddress on your From domain so SPF aligns. - If you send through an ESP that uses its own bounce domain, make sure your DKIM signature is on your domain, not theirs.
Related checks
DMARC · SPF · DKIM · Message type