Suped

How does the absence of DKIM affect email deliverability when SPF is passing and DMARC is aligned?

Summary

The absence of DKIM when SPF is passing and DMARC is aligned typically does not lead to an immediate DMARC failure. DMARC (Domain-based Message Authentication, Reporting, and Conformance) is designed to pass if at least one of its underlying authentication mechanisms, SPF (Sender Policy Framework) or DKIM (DomainKeys Identified Mail), passes and aligns with the organizational domain. This means that if SPF successfully authenticates the sending server and its domain aligns with the 'From' domain in the email header, the email can still be considered DMARC compliant. However, relying solely on SPF without DKIM introduces potential vulnerabilities and can affect long-term deliverability, particularly in scenarios involving email forwarding or when a receiving server has stricter authentication policies.

Suped DMARC monitor
Free forever, no credit card required
Get started for free
Trusted by teams securing millions of inboxes
Company logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logo

What email marketers say

Email marketers often focus on getting their messages to the inbox, and while SPF passing and DMARC alignment seem to cover the basics, many are aware of the subtle impacts of a missing DKIM record. They frequently discuss the importance of comprehensive authentication for reputation and avoiding blocklists, even when initial DMARC checks appear satisfactory.

Marketer view

An Email Geeks Marketer indicates that if you check the 'Show original' feature in Gmail and don't see a DKIM signature, it most likely means the sender has not configured DKIM for their domain.

22 Apr 2023 - Email Geeks

Marketer view

A Marketer from an email forum emphasizes that DKIM is generally important for improving overall email deliverability, even if other authentication methods are in place.

15 May 2023 - Email Forum

What the experts say

Email deliverability experts consistently advocate for a multi-layered approach to email authentication. While DMARC's 'either/or' passing mechanism means SPF can suffice for DMARC alignment, experts highlight that DKIM provides critical resilience, especially for forwarded mail and robust sender reputation. They emphasize that while immediate deliverability might not be impacted, neglecting DKIM is a missed opportunity for stronger protection and long-term inbox placement.

Expert view

An Email Geeks Expert confirms that if SPF is passing and DMARC is aligned, the absence of DKIM will generally not affect deliverability in the common case, but suggests adding it for greater robustness.

22 Apr 2023 - Email Geeks

Expert view

An Expert from SpamResource.com advises that while DMARC's 'either/or' mechanism is convenient, relying solely on SPF leaves a domain vulnerable to certain types of attacks, which DKIM can mitigate.

10 Mar 2024 - SpamResource.com

What the documentation says

According to official documentation and technical specifications, DMARC's core function is to allow a domain owner to specify how email receivers should handle unauthenticated emails based on the results of SPF and DKIM. The key principle is that DMARC passes if *either* SPF or DKIM (or both) authenticate and align with the 'From' domain. While this flexibility exists, documentation often implicitly or explicitly recommends implementing both for optimal security and deliverability, particularly due to the inherent limitations of SPF in certain email flow scenarios like forwarding.

Technical article

DMARC documentation from Autospf.com explains that identifier alignment creates a crucial link between SPF and DKIM authentication flows, which also dictates the DMARC policy applied to illegitimate emails.

24 Jul 2024 - Autospf.com

Technical article

Documentation from Threatcop emphasizes that while DMARC requires either SPF or DKIM alignment, both protocols have their own unique pitfalls, underscoring the benefit of having both for comprehensive coverage.

22 May 2022 - Threatcop

14 resources

Start improving your email deliverability today

Get started