Skip to content

Archive

SPF

2 articles
Cybersecurity 23 Sep 2026 5 min read

DMARC Ties Mail Authentication to the Visible From Domain

Email can carry several domain identities at once. The address displayed in the From header can differ from the envelope sender used by SMTP, while a DKIM signature can name yet another domain in its d= tag. SPF and DKIM authenticate identities from those separate protocol layers; neither mechanism alone requires its authenticated domain to match the domain presented to a recipient in From. Domain-based Message Authentication, Reporting, and Conformance (DMARC), specified in RFC 7489, connects those layers. A receiver evaluates SPF and DKIM, tests domain alignment against the RFC5322.From domain, and obtains a policy published by that domain. A message passes DMARC when at least one qualifying SPF or DKIM path both authenticates successfully and aligns.

Tech 19 Sep 2026 7 min read

SMTP Does Not Grant Sender Identity: From Headers, SPF, DKIM, and DMARC

SMTP answers a transport question: which server accepts this message and relays it toward its destination? It does not, by itself, prove that the address displayed in the message’s From: header belongs to the system that opened the SMTP connection. That distinction explains a common surprise. A mail client can connect to an external SMTP service, authenticate successfully, and submit a syntactically valid message with From: user@gmail.com. The SMTP login proves that the client may use that service. It does not give the service authority over gmail.com.