How a Receiving Mail Server Evaluates SPF, DKIM, and DMARC
A reference diagram for the decision flow a receiving mail server actually follows when evaluating SPF, DKIM, and DMARC on an inbound message — including where alignment, not just individual pass/fail, determines the outcome.
SPF and DKIM are checked independently. DMARC then evaluates whether either one aligns with the visible From address — alignment, not just a pass/fail on SPF or DKIM alone, is what actually determines the outcome.
Last reviewed 2026-09-30
What this shows
The order of operations a receiving mail server performs — SPF check, DKIM check, then DMARC alignment evaluation against both — and why a domain can have valid SPF and DKIM records and still fail DMARC if the authenticated domain doesn’t align with the visible From address.
Intended audience
IT administrators and email/security practitioners configuring or troubleshooting SPF, DKIM, and DMARC.
Methodology
Reflects the evaluation order defined in the relevant email-authentication RFCs (SPF: RFC 7208, DKIM: RFC 6376, DMARC: RFC 7489) as implemented by major receiving mail platforms.
Limitations
Describes the standard evaluation model; individual mail providers may apply additional proprietary reputation/filtering signals beyond SPF/DKIM/DMARC that this diagram does not cover.
Citing this resource
To reference this resource, link directly to this page — e.g. “IT KORR’s How a Receiving Mail Server Evaluates SPF, DKIM, and DMARC, itkorr.com/technical-resources/spf-dkim-dmarc-evaluation-flow.” This page may be linked to and quoted from with attribution; republishing or redistributing the diagram itself requires separate permission.
IT KORR helps regulated and growth-stage businesses operate, secure, and prove the systems this resource describes. Learn about Microsoft 365 Management →