Suped

How do Iterable shared infrastructure and Amazon SES handle SPF alignment and DMARC compliance?

Summary

When sending emails through platforms like Iterable that leverage Amazon SES shared infrastructure, email senders often encounter challenges with SPF alignment and DMARC compliance. These issues primarily stem from the default configuration where the Return-Path (MAILFROM) domain does not align with the From header domain, leading to SPF authentication failures in diagnostic tools. Despite these warnings, DMARC compliance is often maintained due to DKIM (DomainKeys Identified Mail) alignment, which is typically configured and aligned correctly by these services.

Suped DMARC monitor
Free forever, no credit card required
Get started for free
Trusted by teams securing millions of inboxes
Company logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logo

What email marketers say

Email marketers using shared infrastructure with services like Iterable and Amazon SES frequently report seeing SPF non-alignment issues in their deliverability reports. While acknowledging the desire for all green checks, many find that DMARC compliance is still achieved through DKIM. The general consensus is that custom SPF alignment via a custom MAILFROM domain is desirable but often not offered by default on shared pools and may require a shift to dedicated sending infrastructure, which presents its own set of challenges, particularly for high-volume senders.

Marketer view

Email marketer from Email Geeks notes that their deliverability tools, including Google Postmaster Tools, are consistently reporting SPF not present/authenticated errors, despite explanations that SPF is handled via CNAME records. They are looking for ways to achieve an all green status.

16 Jun 2022 - Email Geeks

Marketer view

Email marketer from Email Geeks shares that during a recent interaction with Iterable, it was confirmed that their system, while functioning on SES infrastructure, does not natively provide SPF alignment (setting up MAILFROM) to match the 'From' address. Consequently, only DKIM alignment is achievable for DMARC compliance.

16 Jun 2022 - Email Geeks

What the experts say

Deliverability experts generally concur that a lack of SPF alignment on shared infrastructure, while generating warnings in some testing tools, is often not detrimental to DMARC compliance, provided DKIM alignment is correctly configured. They advise that DMARC can pass if either SPF or DKIM aligns, making DKIM the primary fallback for shared pools. However, they also stress that achieving full SPF alignment (belt and suspenders) offers enhanced redundancy and is a valuable long-term goal to mitigate future deliverability risks, even if it requires more effort.

Expert view

Deliverability expert from Email Geeks, who built KBXSCORE, confirms that SPF does not align as reported by users. They clarify that the report indicates DMARC is passing because each brand has a first-party DKIM signature, meaning DMARC passes based on DKIM alignment, rather than SPF.

17 Jun 2022 - Email Geeks

Expert view

Deliverability expert from Email Geeks states that a lack of SPF alignment on shared infrastructure is quite normal. They add that while it might be frustrating to see errors or warnings in reporting tools, it's likely not causing any actual harm to deliverability.

18 Jun 2022 - Email Geeks

What the documentation says

Official documentation from Amazon SES, Iterable, and DMARC resources clarifies the mechanisms of SPF, DKIM, and DMARC in the context of shared infrastructure. It is stated that DMARC can pass via either SPF or DKIM, with a common configuration for shared services involving strict DKIM alignment and relaxed SPF alignment, or SPF alignment being absent due to the use of a default return-path domain (e.g., amazonses.com). While Amazon SES supports custom MAILFROM domains for SPF alignment, this is an advanced configuration that ESPs built on SES may or may not expose to their users on shared pools.

Technical article

Documentation from DMARC.wiki states that Amazon SES supports DMARC compliance through both SPF and DKIM. It specifies that SES enforces strict alignment on DKIM but only relaxed alignment on SPF, which means the envelope sender domain needs to share an organizational domain with the 'From' header for SPF to pass DMARC.

10 Jan 2023 - DMARC.wiki

Technical article

Documentation from MailBluster clarifies that without a custom MAIL FROM domain, DMARC can only align with DKIM but not with SPF. This is because the 'envelope from' (Return-Path) and 'header from' values will not be the same, preventing SPF from passing alignment checks.

15 Feb 2023 - MailBluster

6 resources

Start improving your email deliverability today

Get started