Field note · 12 min read
How to Test DKIM Alignment: A Simple Guide for Multi-Domain Owners
Learn how to test DKIM alignment on each domain you own, read the raw headers yourself, and fix the mismatches that quietly send your invoices to spam.
To learn how to test dkim alignment, send an email from your custom domain to an external inbox and compare the d= domain in the DKIM-Signature header against the domain in your visible From: address. If those two domains share the same root domain under relaxed alignment, your signature is aligned; if they differ, your signature is unaligned and your DMARC policy cannot use it to pass verification.
When you operate three, five, or ten distinct web properties, this simple rule becomes complicated quickly. Running a quick dkim alignment check across multiple businesses reveals that sending systems often sign messages with their own administrative domain rather than your brand's domain. A message can show a valid mathematical signature, pass an initial cryptographic check, and still cause your wider dmarc alignment test to fail. This guide walks through manual header checks, multi-domain testing workflows, common configuration pitfalls, and how to verify that every domain you manage authenticates cleanly.
The 60-Second DKIM Alignment Check (Do This First)
You do not need to configure an enterprise monitoring console to test a single address. You can complete a manual inspection in sixty seconds using any personal receiving account you control.
- Send a test email from the custom domain you want to evaluate to an external mailbox (such as a personal Gmail, Outlook, or Fastmail address).
- Open the message in your webmail interface and view the raw internet message headers. In Gmail, select the vertical three-dot menu next to the reply button and choose Show original. In Outlook on the web, view message details or select message properties to inspect the internet headers. In Apple Mail, select View > Message > Raw Source.
- Search the raw text for three specific lines:
Authentication-Results:,DKIM-Signature:, andReturn-Path:.
The Authentication-Results: header provides the receiving server's verdict. Look for the DKIM verdict section:
Authentication-Results: mx.google.com;
dkim=pass header.i=@consultingbrand.com header.s=folio1 header.b=ab12CD34;
spf=pass (google.com: domain of bounces@consultingbrand.com designates 198.51.100.24 as permitted sender) smtp.mailfrom=bounces@consultingbrand.com;
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=consultingbrand.com
Next, find the DKIM-Signature: header block and identify the signing domain tag (d=):
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=consultingbrand.com; s=folio1;
h=from:to:subject:date:message-id;
bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=;
b=...
Now compare the d= value in the signature to the domain in your visible From: line:
From: Alice Chen <alice@consultingbrand.com>
If the domain in d= matches the domain in the From: address, DKIM is aligned. If the DKIM-Signature header reads d=mailhostingservice.net while your email address is alice@consultingbrand.com, DKIM is not aligned, even if the header indicates dkim=pass.
If you prefer not to parse raw text by hand, paste the full source into a web-based diagnostic tool. You can inspect your records using the unauthenticated FolioInbox domain health audit, which checks SPF, DKIM, DMARC, and MTA-STS records directly from DNS without requiring an email address or signup.
Perform this check for every domain you manage. When you are a solo operator running five brands—such as an advisory practice, an eCommerce brand, and three regional LLC holding entities—a clean header on your primary consulting domain tells you nothing about the other four. Each domain publishes its own DNS records and routes through its own mail path.
What DKIM Alignment Actually Means (and Why DMARC Cares)
DomainKeys Identified Mail (DKIM) is an asymmetric cryptographic authentication protocol. When your mail server sends a message, it creates a hash of selected headers and the message body, encrypts that hash using a private key stored on the server, and injects the output into the DKIM-Signature header. The receiving server inspects the signature tag d= (the signing domain) and s= (the selector), performs a DNS query for [selector]._domainkey.[signing-domain], retrieves your public key, and verifies the signature.
Cryptographic validity confirms that the message was signed by whoever holds the private key for the d= domain and that the message contents were not altered in transit. However, validity does not confirm identity alignment.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) evaluates whether the identity presented to the human recipient in the visible From: header corresponds to the infrastructure that authenticated the message. Deceptive messages and brand impersonation remain widespread security concerns; as outlined in FTC phishing guidance, malicious senders routinely manipulate sender identities to deceive recipients. Furthermore, FTC guidance on how websites and apps collect and use information underscores the importance of protecting commercial communications against data compromise. Because digital messaging remains indispensable to business operations—an enduring reality highlighted by Pew Research Center research on email use—alignment enforcement protects brand integrity.
Without alignment, an attacker could register spammer-infrastructure.com, sign a fraudulent message with their own valid DKIM key (producing a passing signature where d=spammer-infrastructure.com), and display From: billing@yourbrand.com. Without an alignment requirement, malicious mail could pass DKIM verification while spoofing your company.
DMARC evaluates two authentication mechanisms: SPF and DKIM. For a message to achieve an overall DMARC pass, at least one of these two protocols must achieve both cryptographic validity and identifier alignment with the visible From: domain:
- Relaxed Alignment (
adkim=r, default): The organizational domain (root domain) of thed=tag must match the organizational domain of theFrom:header. For example, a signature whered=mail.consultingbrand.comaligns withFrom: alice@consultingbrand.combecause both resolve to the root organizational domainconsultingbrand.com. - Strict Alignment (
adkim=s): The fully qualified domain name (FQDN) in thed=tag must match theFrom:header domain exactly. Under strict alignment,d=mail.consultingbrand.comfails alignment againstFrom: alice@consultingbrand.com.
Because third-party forwarding, mailing list processors, and automated gateways frequently rewrite envelope sender addresses (breaking SPF), DKIM alignment serves as the primary resilient pillar of modern email authentication. When sending across multiple businesses, each entity must sign messages using a key published under its own specific domain.
Reading the Raw Headers: Worked Examples and Traps
To perform manual email authentication diagnostics, review the exact header structure evaluated by receiving mail exchange (MX) servers. Receiving servers prepend an Authentication-Results: header at the very top of the incoming email.
Example 1: A Passing, Aligned Authentication Block
Authentication-Results: mx.google.com;
dkim=pass header.i=@consultingbrand.com header.s=folio1 header.b=Y2hhcnM4;
spf=pass (google.com: domain of bounces@consultingbrand.com designates 198.51.100.24 as permitted sender) smtp.mailfrom=bounces@consultingbrand.com;
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=consultingbrand.com
Received: by 2002:a05:6808:150b:b0:3c9:8614:260b with SMTP id ...
From: Alice Chen <alice@consultingbrand.com>
To: recipient@example.org
Subject: Quarterly Advisory Agreement
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=consultingbrand.com; s=folio1;
h=from:to:subject:date:message-id;
bh=uW9FpXfE...;
b=Y2hhcnM4...
In this passing example:
- The visible
From:domain isconsultingbrand.com. - The
DKIM-Signaturedomain (d=) isconsultingbrand.com. - The cryptographic check succeeded (
dkim=pass). - Because
d=matchesheader.from, DKIM is aligned. - DMARC evaluates to
dmarc=pass.
Example 2: A Passing Signature with Failed Alignment
Now consider an email sent through a generic shared email platform or secondary address alias where the platform signs using its own default domain:
Authentication-Results: mx.google.com;
dkim=pass header.i=@sharedrelaymail.net header.s=relaysel header.b=kJ82mQ;
spf=softfail (google.com: domain of transitioning user@otherhost.com does not designate 203.0.113.19 as permitted sender) smtp.mailfrom=user@otherhost.com;
dmarc=fail (p=REJECT sp=REJECT dis=REJECT) header.from=consultingbrand.com
From: Alice Chen <alice@consultingbrand.com>
To: client@example.org
Subject: Invoice #1042
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=sharedrelaymail.net; s=relaysel;
h=from:to:subject:date:message-id;
bh=vP19eK...;
b=kJ82mQ...
Examine what happened here:
- The receiving server checked the public key at
relaysel._domainkey.sharedrelaymail.net. The mathematical signature verified cleanly, yieldingdkim=pass. - The DMARC engine compared the
d=value (sharedrelaymail.net) to theFrom:domain (consultingbrand.com). - The domains do not match. DKIM alignment evaluated to false.
- Because the SPF check also failed (or did not align with
consultingbrand.com), the overall DMARC verdict wasdmarc=fail. Under an active quarantine or reject policy, this invoice was routed directly to spam or discarded entirely.
When inspecting headers, look at the Authentication-Results: line injected by the recipient's boundary server. Mail headers read from bottom to top in chronological order: the originating server creates the initial headers at the bottom, and each intermediary server appends its own Received: and analysis blocks above them. Ignore intermediate authentication results generated internally by your own outbound host.
Remember this simple comparison rule: Locate d=, locate From:, and compare the base organizational domains.
Why Multi-Domain Setups Fail DKIM Alignment
Portfolio entrepreneurs, solo founders, and consultants who run multiple brands frequently encounter alignment failures. These failures rarely stem from misunderstandings of cryptography. Instead, they stem from architectural compromises made when trying to avoid paying recurring per-seat fees across multiple accounts.
1. Gmail "Send As" Custom Domain Aliases
A widespread workaround involves purchasing a single primary Google Workspace or Microsoft 365 seat, and then configuring secondary domains as aliases inside a personal Gmail interface using "Send As." When configured via generic SMTP or Google's default outgoing relays, Gmail often signs the outgoing envelope with the default Google domain or the primary Workspace tenant identity.
The resulting message presents From: hello@storebrand.com, but the DKIM signature contains d=primarybrand.com or d=gmail.com. The cryptographic signature passes, but DKIM alignment fails completely. If storebrand.com publishes a DMARC policy of p=quarantine or p=reject, recipient mail systems will penalize the delivery of those messages.
2. Shared Relay Hosts and Cheap Forwarders
Inexpensive forwarding setups forward incoming messages to a private inbox and send outbound messages through a shared SMTP relay. Unless that relay explicitly allows you to generate, store, and select a distinct private cryptographic key for every individual domain, it will sign outgoing messages using a shared administrative domain (such as d=relayprovider.com).
While this allows the relay provider to verify that their servers emitted the message, it gives your custom domain zero DMARC credit. The domain in the From: header remains unaligned with the signature.
3. Third-Party Transactional Platforms
If you operate an eCommerce storefront on Shopify or use transactional senders like Postmark or SendGrid, those platforms send order confirmations and receipts showing your brand in the header. Unless you complete custom domain verification inside those providers by creating designated CNAME records pointing to their DKIM selectors, they sign using their own shared domain (e.g., d=sendgrid.net). The message will pass DKIM mathematically, but fail alignment against your store domain.
Testing DKIM Alignment Across Multiple Domains: A Step-by-Step Workflow
If you manage four or five commercial domains, testing each one individually requires an organized, repeatable process. Follow this testing workflow to verify alignment across your entire portfolio:
Step 1: Inventory Your Outbound Senders
For each domain you control, write down every service that emits mail showing that domain in the From: header:
- Your direct personal mailbox provider (where you write one-to-one sales emails, advisory notes, and invoices).
- Transactional notification engines (such as your eCommerce shopping cart or SaaS application).
- Marketing newsletter tools.
Step 2: Query Public DNS Records for Each Selector
Before sending live test messages, verify that your DKIM public keys are published correctly in DNS. Use command-line tools like dig or nslookup to confirm that your selectors resolve.
For example, if your mail provider assigns the selector folio1 on storebrand.com, query the TXT record at that subdomain:
dig TXT folio1._domainkey.storebrand.com +short
The output must return a valid DKIM public key string beginning with v=DKIM1; k=rsa; p=... or a CNAME pointing to your host's key infrastructure. If the query returns blank, your selector record has not propagated or was pasted into DNS incorrectly.
Step 3: Execute Outbound Test Sends from Every Domain
Do not assume that because your advisory brand passes alignment, your eCommerce brand also passes. Send a single test message from each individual domain to a monitored inbox (such as an external Gmail account).
Open the raw headers for each test message and verify:
- The
DKIM-Signatureheader containsd=[that-specific-domain.com]. - The
From:header matches[that-specific-domain.com]. - The
Authentication-Results:line recordsdkim=pass. - The DMARC result records
dmarc=pass.
Step 4: Audit DMARC Alignment Tags
Inspect your domain's DMARC TXT record at _dmarc.[yourdomain.com]. Look for the adkim tag:
- If
adkim=r(or if the tag is omitted), relaxed alignment applies. Subdomains will align with your organizational domain. - If
adkim=s, strict alignment applies. If you send frombilling.storebrand.com, your DKIM signature must explicitly haved=billing.storebrand.com. A signature withd=storebrand.comwill fail under strict alignment.
Common Misconfigurations and How to Fix Them in DNS
When an alignment check fails, the underlying cause is almost often one of four DNS or mail-host configuration mistakes:
1. Hostname Duplication in DNS Control Panels
Many DNS control panels (such as Namecheap, GoDaddy, or Cloudflare) automatically append your root domain to any record name you create. If your provider instructs you to create a record named folio1._domainkey.yourbrand.com and you paste that entire string into the "Host" field, the registrar may publish folio1._domainkey.yourbrand.com.yourbrand.com.
When the receiving server queries folio1._domainkey.yourbrand.com, it receives an NXDOMAIN response. The cryptographic check fails, alignment cannot be evaluated, and DMARC fails. In your DNS dashboard, enter only folio1._domainkey in the name field unless your provider specifically requires the trailing dot.
2. Truncated 2048-Bit RSA Keys
A 2048-bit RSA key string is typically 390 to 400 characters long. Certain legacy DNS management consoles limit TXT record character strings to 255 characters. If you paste a 2048-bit key into a single string field, the console may truncate the key, corrupting the public exponent.
To resolve this, split the key into two quoted strings inside the single TXT record, or choose a mail provider that manages public keys via CNAME records pointing to their managed DNS endpoints.
3. Broken Alignment Caused by Subdomain Mismatches
If you send from newsletter.yourbrand.com and your DKIM signature is generated with d=yourbrand.com, your alignment will pass under relaxed mode (adkim=r) but fail under strict mode (adkim=s). Unless you have a regulatory reason to mandate strict alignment, maintain relaxed alignment in your DMARC record (v=DMARC1; p=quarantine; adkim=r; aspf=r;).
4. Using a Single Mailbox Account with Multiple Secondary Aliases
If you need to send from five different domains, using one standard consumer inbox or a basic shared host that applies a single generic DKIM key across all outgoing mail will consistently break alignment for your secondary domains.
To solve this without paying separate per-seat software fees across multiple brands, solo operators use dedicated multi-domain systems. For example, Folio is one mailbox that sends and receives across many custom domains, with a separate DKIM key and signature per domain, for a single operator. Folio is a single-operator inbox, not a team or shared mailbox — there are no per-user seats and no team collaboration features. Setup takes place on a single screen, and at registrars that support Domain Connect, DNS records are published automatically.
Pricing is flat per plan rather than billed per user seat. According to published FolioInbox plan specifications, plans scale flatly by domain count and monthly send allowance rather than user seats: the Solo tier accommodates up to 3 domains, Studio expands coverage up to 10 domains, and Folio Holding Co. supports unlimited domains. Folio has no free plan. A free preview of 100 sends on one domain, no card required. Paid plans (Solo, Studio, Holding Co.) start with a 14-day trial, card required. When evaluating email platforms across your businesses, compare the per-domain cost of dedicated multi-domain tools against traditional per-seat suites.
Frequently Asked Questions
What is the difference between DKIM verification and DKIM alignment?
DKIM verification is a mathematical check. The receiving mail server uses the public key published in your DNS records to decrypt the signature and confirm that the message body and headers were not modified during transit. DKIM alignment is an identity check enforced by DMARC. It checks whether the signing domain specified in the d= tag matches the domain shown in the visible From: header. A message can pass DKIM verification while failing DKIM alignment.
Can DMARC pass if DKIM alignment fails?
Yes. DMARC requires either SPF or DKIM to pass both verification and alignment. If your DKIM signature fails alignment, your message can still achieve an overall dmarc=pass if your SPF check passes and your SPF envelope sender (Return-Path) aligns with the visible From: domain. However, relying solely on SPF is fragile because message forwarding and email distribution lists routinely rewrite the Return-Path, causing SPF to fail downstream.
What does "relaxed" versus "strict" DKIM alignment mean?
Relaxed alignment (the default setting in DMARC, written as adkim=r) allows subdomains to align
§ Related guides
- Best email hosting for multiple websites Compare pricing, domain limits, authentication, and inbox workflow for several websites.
- Stop email spoofing How Folio files unverifiable senders before they reach the inbox.
- DMARC reports across every domain See failing sources, pass rates, and when to tighten policy.
- Free email domain health check Check MX, SPF, DKIM, and DMARC before changing providers.