New to DMARC? Start with the fundamentals →
You moved DMARC to an enforcing policy, and then your newsletter stopped landing — or your password-reset emails started bouncing. The platform swears it authenticates your mail, and technically it's right. The problem is a subtle one that catches nearly every team: passing authentication isn't the same as aligning to your domain.
Mailchimp, SendGrid, HubSpot, Klaviyo, and every other email service send mail on your behalf — but out of the box, that mail authenticates as their domain, not yours. Here's why that fails DMARC, and exactly what to fix for each platform.
Why ESP mail fails alignment by default
When you send through an ESP without configuring your domain, the message goes out something like this: the envelope and DKIM signature use the platform's own domain (mailchimpapp.net, sendgrid.net, and so on), while the visible From: shows you@yourdomain.com.
That mail will happily pass SPF and DKIM — on the platform's domain. But DMARC doesn't care that authentication passed somewhere; it requires the authenticated domain to align with the domain in your From: header. Platform-domain authentication plus your-domain From: equals an alignment failure, every time. If the concept is fuzzy, our DMARC alignment explainer breaks it down.
At p=none you never notice — failures are reported, not enforced. The day you move to quarantine or reject, that unaligned mail starts getting filtered or refused. Which is why teams so often blame the policy change, when the real cause was unconfigured senders all along.
The fix: a custom domain + your-domain DKIM
Every reputable platform supports sending as your domain. The setup has two parts, and both are just DNS records the platform hands you:
- A custom sending / return-path domain. Instead of the platform's bounce domain, you delegate a subdomain of yours (often something like
mail.yourdomain.comorem.yourdomain.com) via CNAME records. This aligns the SPF/return-path side to your domain. - DKIM signing on your domain. The platform gives you one or more CNAME (or TXT) records that let it sign with a key under your domain. This aligns the DKIM side.
Publish the records, let DNS propagate, and verify inside the platform. From then on the platform signs and authenticates as you — and DMARC aligns. The mechanics of the signing side are in what DKIM is.
One nuance worth knowing: DMARC's default relaxed alignment passes if either SPF or DKIM aligns to your domain, so aligned DKIM alone is often enough for a pass. Configure both anyway — aligned DKIM survives forwarding and mailing lists where SPF breaks, so two aligned mechanisms are what keep you passing everywhere, not just when the ESP sends to you directly.
Platform by platform
The names differ, the idea is identical — find the platform's "authenticate your domain" or "verified sending domain" setting:
- Mailchimp — verify your domain, then publish the DKIM and return-path CNAMEs from Domains settings so mail aligns instead of using
mailchimpapp.net. - SendGrid — "Sender Authentication" → "Authenticate Your Domain" generates the CNAMEs for a branded link and DKIM/return-path on your domain.
- HubSpot — connect your email sending domain so HubSpot signs DKIM and sets the return-path on your domain rather than HubSpot's.
- Others (Klaviyo, Amazon SES, Zoho, etc.) — all have an equivalent "dedicated/authenticated sending domain" flow. If you don't see one, you're not aligned.
Generate or sanity-check your DMARC record while you're in your DNS with the free DMARC generator.
Verify alignment before you enforce
Don't trust the platform's green checkmark alone — confirm in your DMARC aggregate reports. Each ESP should appear as a source that passes DMARC with the authenticated domain aligned to your From:. If a platform still shows dkim=pass but DMARC fail, its DKIM is signing on the wrong domain and the custom-domain step isn't finished.
Only once every legitimate platform shows aligned in the reports should you move p=none toward quarantine and reject. Otherwise you'll enforce against your own mail.
Frequently asked questions
Why does my Mailchimp or SendGrid email fail DMARC?
Because by default it authenticates as the platform's domain, not yours. The mail passes SPF and DKIM on the ESP's own sending domain, but DMARC requires the authenticated domain to align with your visible From: address. Until you configure a custom authenticated domain and your-domain DKIM on the platform, that alignment is missing and DMARC fails.
How do I align a third-party sender with DMARC?
In each platform, set up a custom sending/return-path domain on your own domain and enable DKIM signing for your domain — both are done by publishing the CNAME or TXT records the platform provides. Once those propagate, the platform signs and authenticates as you, the From: aligns, and DMARC passes. Confirm it in your aggregate reports before enforcing.
Third-party senders are where most DMARC rollouts stall, because the failures look like the policy's fault when they're really configuration. Authenticate each platform as your own domain, confirm alignment in your reports, and the enforcing policy stops being scary. See which senders are aligned under your domain and fix the ones that aren't.