What does the DMARC adkim tag do?

The DMARC adkim tag chooses how closely a passing DKIM signing domain must match the visible From domain. adkim=r is relaxed alignment and is the default when the tag is omitted. Related subdomains can align when they share the same Organizational Domain. adkim=s is strict alignment and requires an exact domain match. The tag does not make DKIM pass, change the DKIM key, or affect SPF alignment. Test every production sender before moving to strict mode.
Quick takeaways
- adkim controls DKIM identifier alignment for DMARC.
- Relaxed alignment, adkim=r, is the default.
- Strict alignment, adkim=s, requires an exact domain match.
- The comparison uses a passing DKIM signature's d= domain and the visible From domain.
- A stricter setting can break DMARC for legitimate subdomain or parent-domain signing.
This diagram summarizes the article's diagnostic sequence. Use the linked standards, current provider documentation, and production evidence for exact decisions. Open the full-size diagram.
Who is affected?
The tag affects domains that rely on DKIM to satisfy DMARC, particularly when third-party services sign with a parent domain, sending subdomain, or provider-owned domain. It also affects MSPs applying one DMARC template across clients with different signing designs.
Review the DKIM overview and DMARC overview before changing the mode. A DNS record alone cannot show every signing domain used in production.
What are the requirements?
RFC 9989 defines adkim as optional. The value r selects relaxed mode and is the default. The value s selects strict mode.
In relaxed mode, the DKIM authenticated identifier and Author Domain can align when their Organizational Domains are the same. A signature with d=mail.example.com can therefore align with From example.com when policy discovery identifies the same Organizational Domain.
In strict mode, the domains must match exactly. That same d=mail.example.com signature does not strictly align with From example.com. It can strictly align with From mail.example.com.
The signature must pass DKIM before alignment helps DMARC. adkim does not repair an invalid signature and does not change the separate SPF alignment mode controlled by aspf.
When does the requirement take effect?
The selected mode applies when a receiver evaluates a passing DKIM signature against the visible From domain under the discovered DMARC policy. Omitting adkim applies relaxed mode.
A change to strict mode can affect the next messages evaluated after receivers obtain the new DNS record. Cached policy records can create a transition period, so observe both headers and aggregate data.
How do I implement the requirement?
1. Inventory every DKIM signing domain
Use delivered messages and aggregate reports to list the passing d= value for every mailbox, campaign, billing, support, and alert source.
2. Compare each value with the From domain
Mark which signatures align only through the Organizational Domain and which are exact matches. Do not infer the signing domain from a DNS selector inventory.
3. Fix legitimate non-aligned senders
Enable a custom DKIM domain where supported, change the visible From domain deliberately, or rely on a separately aligned SPF path while keeping DKIM healthy.
4. Publish the chosen mode once
Use adkim=r for relaxed behavior or adkim=s for strict behavior in the single DMARC policy record. Preserve other approved policy and reporting tags.
5. Roll out strict mode with evidence
If strict alignment is required by policy, test low-risk sources first and watch normal traffic before treating the change as complete.
How do I validate compliance?
For each source, inspect a delivered message and confirm DKIM pass, the expected d= value, the visible From domain, and DMARC pass. Check aggregate data for sources that appear infrequently and for any new strict-alignment failures.
Use the DNS lookup tool to verify the policy and selectors, then Email Security Score for public configuration. Production messages and reports are the evidence that every sender still aligns.
Frequently asked questions
Keep going with AI
Ask AI how this applies to you
Take this guide to your assistant — each question opens pre-filled, with a link back to this page so it can read the details.

Written by
Samuel ChenardCEO & Co-Founder, Palisade
Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.
More from Samuel →


