Why does Brevo not provide SPF alignment by default?

Brevo's domain setup documentation explains that its standard flow can use Brevo's generic return-path infrastructure, so SPF passes for a Brevo-controlled domain rather than aligning with your visible From domain. That is not automatically a DMARC failure because Brevo can provide an aligned DKIM pass for your authenticated sender domain. Brevo's newer branded subdomain setup moves SPF and return-path identity onto a customer domain, but Brevo says that flow is still rolling out. Verify the options shown in your account and test an actual message.
Quick takeaways
- SPF pass and SPF alignment are different results.
- Brevo's generic return path can pass SPF for Brevo's domain.
- An aligned DKIM pass can still make DMARC pass.
- Branded subdomain setup can provide customer-domain SPF alignment where available.
- Copy account-generated DNS values and verify a delivered message before changing policy.
This diagram summarizes the article's diagnostic sequence. Use the linked standards, current provider documentation, and production evidence for exact decisions. Open the full-size diagram.
What does the failure mean?
The common header pattern is SPF pass for a Brevo return-path domain, DKIM pass for the customer's authenticated domain, and DMARC pass through DKIM. A checker that reports SPF unaligned is describing only one DMARC path.
RFC 9989 requires at least one aligned passing method for DMARC to pass. Review the SPF overview, DKIM overview, and DMARC overview before treating dual alignment as mandatory.
What usually causes it?
The account uses Brevo's generic return path
Brevo's authentication guide documents that ordinary domain authentication can continue to use its generic SPF and return-path infrastructure. The SPF-authenticated domain therefore does not match the customer's From domain.
DKIM authentication is incomplete
If the account-generated CNAME or TXT records are missing, stale, or attached to a different sender domain, the aligned method can fail and expose the unaligned SPF path.
The sender domain differs from the authenticated domain
Brevo warns that using a completely different authenticated domain breaks DMARC alignment. A subdomain mismatch can also matter under strict alignment.
How do I diagnose the failure?
1. Inspect the Brevo domain state
Open the current domain setup for the exact sender domain. Record whether the account shows the standard authentication flow, a branded subdomain option, or dedicated-IP requirements.
2. Read a delivered message header
Record smtp.mailfrom, SPF result, DKIM d= domain and selector, visible From domain, and DMARC result. Identify which method actually supplied alignment.
3. Verify account-generated DNS values
Compare every DKIM or branded-subdomain record with the values displayed in this Brevo account. Never reuse values from another tenant or an article example.
4. Check alignment mode
Read adkim and aspf in the applicable DMARC policy. Strict alignment can reject a domain relationship that passes under relaxed mode.
How do I fix it?
First restore aligned DKIM by completing Brevo's current domain-authentication workflow for the exact sender domain. If the account offers branded subdomain setup and the organization needs SPF alignment, follow Brevo's account-specific flow to delegate the return path and related infrastructure.
Do not add a guessed Brevo include to the visible From domain and assume alignment is fixed. SPF is evaluated at the actual envelope domain. Do not replace an existing DMARC record with a generic vendor record without reviewing the current policy and report destinations.
How do I validate the repair?
Send a new Brevo message from the affected sender domain to an independent mailbox. Confirm DKIM pass and alignment, then check whether SPF alignment changed if a branded subdomain was configured. Verify DMARC pass and monitor aggregate data for all Brevo streams.
Use Palisade's DNS lookup tool for exact record names and Email Security Score for public configuration. Brevo account status plus message headers provide production proof.
Frequently asked questions
Keep going with AI
Ask AI how this applies to you
Take this guide to your assistant — each question opens pre-filled, with a link back to this page so it can read the details.

Written by
Samuel ChenardCEO & Co-Founder, Palisade
Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.
More from Samuel →


