# SPF fail for alias domain

**URL:** <https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028>\
**Category:** Community Area\
**Created:** [January 13, 2020, 9:12pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028 "2020-01-13T21:12:31Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sbollini](https://avatars.discourse-cdn.com/v4/letter/s/b9bd4f/32.png) [@sbollini](https://forum.dmarcian.com/u/sbollini)\
**Post date:** [January 13, 2020, 9:12pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/1 "2020-01-13T21:12:31Z")

</div>

Hi all!  
I have 2 domains hosted at gmail, let’s say “zxc[.]net” and “zxc[.]com”, the second being an alias of the first. DMARC reports I receive for zxc[.]net say everything is fine, but reports for zxc[.]com say that spf “fail-unaligned” because (if I correctly understand it) when I send mail from and address at zxc[.]com, smtp header says “zxc[.]com” but HELO command says “zxc[.]net”.  
Does anybody know if it’s possible to configure SPF record to accommodate this situation?

Kind regards

---

<div class="post-metadata">

**Author:** ![UffeA](https://avatars.discourse-cdn.com/v4/letter/u/b5e925/32.png) [@UffeA](https://forum.dmarcian.com/u/UffeA)\
**Post date:** [January 16, 2020, 8:36am UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/2 "2020-01-16T08:36:53Z")

</div>

SPF is only checked against HELO if the mails doesn’t contain a Return-Path header. If Return-Path is present, it will be used for SPF check and therefore you need to look into, how you align your Return-Path with your “From: Domain”. Keep in mind that SPF can be perfectly valid, while still being unaligned from a DMARC perspective.  
Regards  
/Uffe

---

<div class="post-metadata">

**Author:** ![sbollini](https://avatars.discourse-cdn.com/v4/letter/s/b9bd4f/32.png) [@sbollini](https://forum.dmarcian.com/u/sbollini)\
**Post date:** [January 16, 2020, 4:56pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/3 "2020-01-16T16:56:18Z")

</div>

Thanks for your tip! I’ll try it.

Kind regards

---

<div class="post-metadata">

**Author:** ![Tomki](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/tomki/32/45_2.png) [@Tomki](https://forum.dmarcian.com/u/Tomki)\
**Post date:** [January 17, 2020, 12:48am UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/4 "2020-01-17T00:48:06Z")

</div>

@UffeA’s feedback is mostly correct, but with a common misconception.  
SPF checks do _NOT_ perform against the ‘Return-Path’ header. They are performed against the value of the mail-from SMTP element. The Return-Path header appears amongst headers of messages simply to reflect what the mail-from was, and each hop that the message transits can change the Return-Path header value based on what _actually_ happened during SMTP.

A source of confusion on this topic is that some people call the mail-from ‘returnpath’ interchangeably. (also ‘bounce address’, ‘rfc5321.from’, ‘rfc5321.mailfrom’)

So to resolve the stated issue, you must update the sending behaviour to actually use the same domain in mailfrom as appears in the From: header (rfc5322.From). To note, the mailfrom domain in use may be a subdomain of the From domain, so that you can usefully segregate SPF records. (This is assuming your DMARC record is set with relaxed alignment, which is the default behaviour)  
e.g.  
mailfrom value of [tomki@support.dmarcian.com](mailto:tomki@support.dmarcian.com)  
From value of [tomki@dmarcian.com](mailto:tomki@dmarcian.com)

Use of a subdomain this way would mean that you must have a specific SPF allowance at the DNS TXT location for [support.dmarcian.com](http://support.dmarcian.com).

–Tomki

---

<div class="post-metadata">

**Author:** ![sbollini](https://avatars.discourse-cdn.com/v4/letter/s/b9bd4f/32.png) [@sbollini](https://forum.dmarcian.com/u/sbollini)\
**Post date:** [January 17, 2020, 1:00pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/5 "2020-01-17T13:00:13Z")

</div>

Thanks Tomki!  
The point is that the 2nd domain is not a sub domain of the 1st one: the addresses are [me@zxc.com](mailto:me@zxc.com) and [me@zxc.net](mailto:me@zxc.net), both addresses belonging to the same organization.

So, you say I’ll not fix this issue making Replay-to equal to From?

---

<div class="post-metadata">

**Author:** ![Tomki](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/tomki/32/45_2.png) [@Tomki](https://forum.dmarcian.com/u/Tomki)\
**Post date:** [January 17, 2020, 4:18pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/6 "2020-01-17T16:18:54Z")

</div>

Right, you cannot fix the issue by changing message headers. You must change sending server/application behaviour.  
If you have correct DKIM signing on this traffic (DKIM key for the same domain as the From header), the traffic will still pass DMARC successfully.

---

<div class="post-metadata">

**Author:** ![sbollini](https://avatars.discourse-cdn.com/v4/letter/s/b9bd4f/32.png) [@sbollini](https://forum.dmarcian.com/u/sbollini)\
**Post date:** [January 17, 2020, 8:37pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/7 "2020-01-17T20:37:46Z")

</div>

> [@Tomki](#):
>
> Right, you cannot fix the issue by changing message headers. You must change sending server/application behaviour.

You mean the HELO?

> [@Tomki](#):
>
> If you have correct DKIM signing on this traffic (DKIM key for the same domain as the From header), the traffic will still pass DMARC successfully.

Should my problem be solved if both domains have the same DKIM signature?

---

<div class="post-metadata">

**Author:** ![opvind](https://avatars.discourse-cdn.com/v4/letter/o/e274bd/32.png) [@opvind](https://forum.dmarcian.com/u/opvind)\
**Post date:** [January 19, 2020, 10:59pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/8 "2020-01-19T22:59:56Z")

</div>

@Tomki, I’ll agree that the myriad of names for rfc5321.mailfrom _is_ confusing, but isn’t ‘common misconception’ a bit harsh?

An explanation for the many names can be found at [https://dmarc.org/2016/07/how-many-from-addresses-are-there/](https://dmarc.org/2016/07/how-many-from-addresses-are-there/)

---

<div class="post-metadata">

**Author:** ![Tomki](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/tomki/32/45_2.png) [@Tomki](https://forum.dmarcian.com/u/Tomki)\
**Post date:** [February 3, 2020, 11:56pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/9 "2020-02-03T23:56:20Z")

</div>

> [@sbollini](#):
>
> > [@Tomki](#):
> >
> > Right, you cannot fix the issue by changing message headers. You must change sending server/application behaviour.
> 
> You mean the HELO?

Not really; SPF checks work by default on the mail-from, falling back to the HELO content only if the mail-from was empty.

> [@sbollini](#):
>
> > [@Tomki](#):
> >
> > If you have correct DKIM signing on this traffic (DKIM key for the same domain as the From header), the traffic will still pass DMARC successfully.
> 
> Should my problem be solved if both domains have the same DKIM signature?

I don’t understand that question. DMARC-DKIM will pass if a) the raw signature verification itself passes and b) the signature attached in the DKIM-Signature header was done with the same domain as the domain in the From header of the message. (subdomain relationships work too, if the DMARC default adkim=r is unchanged)

---

<div class="post-metadata">

**Author:** ![Tomki](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.dmarcian.com/tomki/32/45_2.png) [@Tomki](https://forum.dmarcian.com/u/Tomki)\
**Post date:** [February 3, 2020, 11:58pm UTC](https://forum.dmarcian.com/t/spf-fail-for-alias-domain/1028/10 "2020-02-03T23:58:42Z")

</div>

@opvind Sorry, I didn’t mean to come across that way. It is simply that I do have the impression that it is a common misconception. 🙂  
Thanks for the link, that is a useful resource.
