Google May Require Both SPF and DKIM Alignment: What Email Senders Should Know
Reviewed against Google’s documentation on 5 October 2026.
Your email can pass DMARC today while relying on only one aligned authentication method. Google recommends a stronger setup: align both SPF and DKIM with the domain recipients see in the From address.
Its sender FAQ says:
“It’s likely that DMARC alignment with both SPF and DKIM will eventually be a sender requirement.”
That is a signal to prepare. Google’s cited guidance does not provide an enforcement date for dual alignment, and it does not identify when this wording was added. Treat it as an existing recommendation, rather than a newly announced rule.
What Gmail requires today
For bulk senders delivering directly to personal Gmail accounts, Google requires SPF, DKIM, and DMARC. Both SPF and DKIM authentication must be configured, but only one authenticated domain needs to align with the visible From domain to meet the current alignment requirement.
These are two different checks:
- Authentication: Does the sending server pass SPF, and does the message have a valid DKIM signature?
- Alignment: Do the authenticated domains match the visible From domain under the applicable DMARC alignment mode?
An SPF pass does not automatically mean SPF is aligned. The same applies to DKIM.
Source: Google’s email sender guidelines and sender FAQ.
What SPF and DKIM alignment mean
SPF checks whether a sending server is authorized for the envelope sender domain, also called the MAIL FROM domain. This is commonly reflected in the delivered message’s Return-Path.
DKIM verifies a digital signature associated with the domain in the signature’s d= value.
DMARC compares those authenticated domains with the visible From domain. Under relaxed alignment, they can share the same organizational domain. Under strict alignment, they must match exactly.
For example, consider this illustrative setup:
| Message identity | Domain |
|---|---|
| Visible From address | [email protected] |
| Envelope sender | bounce.example.com |
| DKIM signing domain | example.com |
Assuming SPF and DKIM both pass, both align under relaxed alignment. With strict SPF alignment, however, bounce.example.com and example.com do not match exactly.
Dual alignment and strict alignment are separate concepts. Preparing both authentication paths does not require changing DMARC to strict mode.
Source: DMARC specification, RFC 9989.
How a message can pass DMARC without dual alignment
Imagine your marketing provider uses these domains:
| Check | Illustrative result |
|---|---|
| Visible From | [email protected] |
| SPF-authenticated domain | provider.example.net |
| DKIM-authenticated domain | example.com |
| SPF authentication | Pass |
| DKIM authentication | Pass |
| SPF alignment | Fail |
| DKIM alignment | Pass |
The message can pass DMARC through aligned DKIM, even though SPF authenticates an unrelated provider domain.
To prepare this sending stream for dual alignment, investigate whether the provider supports a custom MAIL FROM or bounce domain such as bounce.example.com. Follow its DNS instructions, then test a real message.
Adding an SPF include to your website domain alone does not change the envelope sender domain a provider uses.
Why preparing now makes sense
Our practical recommendation is to audit alignment before a provider change or large campaign makes the issue urgent.
Teams often use several services: a newsletter platform, a transactional API, a CRM, a helpdesk, and business mailboxes. Each can use different envelope sender and DKIM domains. A successful test from one service tells you little about another.
Build a simple inventory for every sending stream:
| Sending stream | From domain | SPF domain | DKIM domain | Both aligned? |
|---|---|---|---|---|
| Marketing campaigns | Record actual value | Record actual value | Record actual value | Check |
| Password resets | Record actual value | Record actual value | Record actual value | Check |
| CRM messages | Record actual value | Record actual value | Record actual value | Check |
| Support notifications | Record actual value | Record actual value | Record actual value | Check |
This gives your team a concrete list of configuration gaps to resolve.
A practical preparation checklist
1. Inspect real messages
Send a message from each service to a Gmail test account. Open the message’s original headers and record the visible From domain, smtp.mailfrom domain, DKIM header.d domain, and authentication results.
Do not stop at “DMARC: PASS.” Identify which authentication path produced that result.
2. Ask providers about custom domains
For each unaligned stream, ask whether the service supports a custom MAIL FROM domain and DKIM signing with your domain.
Confirm plan restrictions, setup steps, and how the service behaves if custom-domain DNS becomes unavailable.
3. Test after configuration changes
Retest actual campaign and transactional messages. Check the domain identities as well as SPF, DKIM, and DMARC results.
Repeat testing when you change providers, migrate domains, or modify sending infrastructure.
4. Monitor authentication over time
Use DMARC aggregate reports to discover unfamiliar sending sources and authentication gaps. Combine that information with Gmail Postmaster Tools and your provider’s delivery logs.
For a sending platform, a useful dashboard should expose SPF authentication, SPF alignment, DKIM authentication, and DKIM alignment separately.
What dual alignment will not solve
Authentication validates domain use. It does not guarantee inbox placement.
Recipient expectations, complaint rates, list quality, and sending practices still matter. Google also requires appropriate unsubscribe support for bulk marketing traffic and valid sending infrastructure.
Email verification and authentication solve different problems. Listclean can help identify invalid and risky recipient addresses before sending. SPF, DKIM, and DMARC help receivers evaluate the sender’s domain identity. A healthy sending process needs attention to both.
Frequently asked questions
Is dual alignment mandatory today?
Google’s cited FAQ still permits alignment through either authenticated SPF or authenticated DKIM for direct bulk mail.
Has Google announced a deadline?
The cited guidance does not specify one. Check Google’s official documentation before making time-sensitive compliance claims.
Does this mean changing DMARC to p=reject?
No. DMARC policy and alignment are different settings. Google’s current bulk-sender requirements allow a policy of p=none. Review legitimate sending sources before strengthening enforcement.
Does this apply identically to forwarded messages?
No. Google’s FAQ treats forwarded and mailing-list traffic separately from direct mail. Test those flows separately.
Prepare your sending domains before the requirement changes
Start with an inventory of your sending services, test their actual messages, and resolve alignment gaps where your providers support it.
For your next campaign, check both sides of email quality: authenticate your sending domain and verify your recipient list.
Clean your email list with Listclean.
