Google, Alignment and DMARC

G

Google has been making a number of changes to their systems over the last few weeks. Folks are seeing a lot of changes in Google postmaster tools and they’re seeing changes in how Google is displaying headers in the “show original” tab.

One thing that some folks were seeing is a message that says:

A screenshot from "Show Original" at google that says:

SPF: Pass with IP 104.224.223.158
DKIM: 'Pass: with domain wordtothewise.com
Alignment: The From header Laura Atkins <laura@carrotcafe.com> does not match the DKIM domain wordtothewise.com. Be careful with this message as the sender may be spoofing the From header identity.

This “Alignment” description replaced the DMARC verdict in the header. The interesting thing here is that while DKIM doesn’t align, SPF does pass and so the message technically passed DMARC.

Mike J. on the emailgeeks slack channel mentioned that he noticed that this only seemed to happen when there wasn’t a DMARC policy published for the domain. Well, I can test that! I have multiple domains that do align with SPF, don’t align with DKIM and don’t have current DMARC policies.

We published a DMARC p=none policy for carrotcafe.com and I repeated the test send.

A screenshot from "Show Original" at google that says:

SPF: Pass with IP 104.224.223.158
DKIM: 'Pass: with domain wordtothewise.com
DMARC: 'Pass'

So, yeah, that’s pretty definitive. The “alignment” warning pops up when DKIM doesn’t align and when there is no DMARC record published in DNS. If there is a DMARC record published in DNS, then the DMARC results take precedence.

Of course, as a scientist I would be remiss if I didn’t point out what I didn’t test. The conditions I don’t have the ability to test right now are DKIM aligned and passing with no DMARC record. My hypothesis / gut feel is that it would say DMARC pass, but without running the test I can’t say that’s what is happening.

Word of caution, though. These displays and reports do seem to be a bit buggy. Another email geek posted a screenshot that showed DKIM passing and aligned but also with the Alignment warning. In this case the alignment warning said “The From header of @email.example.com does not match DKIM domain email.example.com.” Which is clearly wrong. That message was double DKIM signed, by the customer and by the ESP domain, so it’s possible that there is a bug that needs to be fixed by the developers.

Overall, I think Google is testing how they’re displaying things specifically to the email deliverability space. Most folks don’t look at the “original display” for their emails. I’d even wager the vast majority of folks who do look at this are in deliverability, email, security or some other technology adjacent field. This is something they’re working out how best to show information.

One important thing to remember: the actual headers of these messages show the messages are correctly authenticated. Also, there seem to be no deliverability consequences (yet!) to the lack of alignment. Currently this is a display issue only. I think it does indicate that Google are serious about expecting folks to have DMARC records, even if they’re p=none. I also think it’s telling that they are putting much more value on DKIM passing and they’re ignoring SPF passing in the instance of no DMARC record.

I’ve been saying for more than a year that deliverability is in an era of upheaval and change and I think this is another example of it. We’re not sure what Google is doing, nor what it means. We just need to be a bit patient and keep our eyes open for what’s going on. I do expect it’s going to be a little longer before things settle down. But that’s OK, we’ve done this before, we can do it again.

About the author

Add comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

By laura

Recent Posts

Archives

Follow Us