Glossary

What Is Domain Alignment?

The DMARC rule that ties SPF and DKIM passes to the domain your recipient sees in the From line.

Get your free API key →Free to start. No credit card. 1,000 records to spend whenever you like.

Domain alignment is the DMARC requirement that the domain authenticated by SPF or DKIM matches the domain in the message's visible From header.

RFC 7489 (September 2026), the DMARC standard, calls this identifier alignment. A message passes DMARC when SPF or DKIM passes and that passing domain is aligned. One aligned pass is enough.

There are two modes, set in your DMARC record. Relaxed (the default) lets the two domains share an organizational domain, so mail.acme.com aligns with acme.com. Strict needs an exact match. The tags are aspf for SPF and adkim for DKIM.

Why it matters for outbound

Passing SPF or DKIM on its own is not enough. If your sending tool signs mail with its own domain, DKIM passes but is not aligned with your From domain, and DMARC fails.

Under a p=quarantine or p=reject policy, that mail goes to spam or is refused. Cold outbound runs on fresh domains and third-party senders, so this is where the misconfigurations happen. A forwarded or relayed message can also break SPF alignment, which is why DKIM is the safer mechanism to align. Check alignment on every sender before you raise the policy. See domain reputation for what failed mail does to a sending domain.

Example

You send from jane.doe@acme.com through a sending tool. The message headers show:

code
From: Jane Doe <jane.doe@acme.com>
Return-Path: <bounce@mailer.example-sender.net>
DKIM-Signature: d=acme.com; s=sel1
Authentication-Results: spf=pass smtp.mailfrom=mailer.example-sender.net;
  dkim=pass header.d=acme.com; dmarc=pass header.from=acme.com

SPF passes, but for example-sender.net, which does not align with acme.com. DKIM passes for acme.com, which does. One aligned pass is enough, so DMARC passes.

Remove the DKIM key and the same message fails DMARC, even though SPF still says pass.

The fix is to set up a custom return-path domain, such as bounce.acme.com, with your sending tool. Then SPF aligns too, and you have two aligned passes instead of one.

In LeadOcean data

LeadOcean has no field, filter or endpoint for domain alignment. Alignment describes your sending setup. LeadOcean data describes the people you send to.

Check alignment in the message headers or in your DMARC aggregate reports. Each sending tool needs its own check, because each one signs and bounces mail its own way. Send a test to a mailbox you own and read the Authentication-Results header before any campaign goes out. For the recipient side, read email_status through /v1/people/search or the search_leads MCP tool, and mail only verified, catch-all valid or catch-all addresses. See pricing for the plans.

More definitions are in the glossary.

Send aligned mail to addresses you can trust

Free to start. No credit card. 1,000 records to spend whenever you like.

Get your free API key →