What this check looks at
Before grading anything else, JoltMx classifies how the message arrived, from signals in the headers and envelope. The path determines which authentication results are healthy and which are genuinely broken:
- Direct - sent straight from the origin to us. Authentication reflects the true sender with no caveats.
- Forwarded - relayed by an intermediary. SPF almost always fails; DKIM survives only if untouched.
- Mailing list - sent via a list that often rewrites the sender and may modify the body.
- Bounce - a delivery-status notification with an empty envelope sender (
MAIL FROM:<>). - Auto-submitted - auto-replies, vacation notices, system alerts.
- Resent - re-introduced with
Resent-*headers.
Why it matters
Most "why is my mail failing?" panic is misdirected. A forwarded message showing SPF: fail isn't misconfigured - that's how forwarding works, and the fix is to make sure DKIM survives and ARC is sealed, not to fiddle with SPF. Telling you the path up front stops you chasing the wrong problem.
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| Direct mail | Pass | The healthy default - results reflect the true origin. |
| Forwarded / list / bounce / auto / resent | Info | Not a fault in itself - context for reading the other findings. |
The delivery path is never graded as a Warning or Critical on its own. It simply frames everything below it.
What to expect per path
Forwarded mail
- SPF almost always fails - the forwarder's IP isn't in the original domain's record. This is normal.
- DKIM survives only if the forwarder leaves the signed headers and body untouched.
- DMARC passes only when DKIM stays aligned, or an intact ARC chain lets the receiver recover the original result.
Mailing-list mail
- The list usually rewrites the envelope sender to its own domain, so SPF aligns with the list, not the author.
- Lists that add subject tags or footers break the author's DKIM signature.
Bounces
The empty envelope sender is required by RFC 5321 to stop bounce loops. It's not a misconfiguration, and SPF can't be evaluated against it.