SPF DKIM DMARC SRS ARC

Why rewriting the visible From address can break DKIM and DMARC

DMARC aligns to Header From. Change it and the author’s signature no longer counts. Do not call that SRS.

MailerZ editorial · Secuno LLC17 min read

Rewrite From breaks DKIM and DMARC because DMARC compares authentication to the domain in Header From. Change that address and the author’s DKIM no longer aligns. Your hop SPF may pass and still fail DMARC. Email authentication is then noisy. Deliverability gets worse, not better. Forwarding authentication is not an SLA. MailerZ uses envelope SRS only and never rewrites Header From. Leftover registrar toys that rewrite are a hard stop until deleted.

Header From changed, DKIM no longer aligns
The signature was over a different From.

Quick answer for rewrite from breaks dkim dmarc

Do not rewrite Header From on inbound. Use exclusive MailerZ MX. Probe from another mailbox. Confirm From is still the author and read dkim and dmarc. That is how you avoid rewrite From breaks DKIM DMARC.

SRS may change the envelope. That is not a visible From change.

p=reject plus a rewrite hop is a bounce machine.

Privacy masks that need a provider From are a different product.

MailerZ Free is one domain, three aliases, one seat, a 14-day store, send-as disabled, SMTP and API disabled, and unrouted mail held or rejected only. Solo is $40 per year only. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise.

Google’s own Send mail as steps live in Google Gmail Help — Send mail from a different address. Workspace as a product is described on Google Workspace — product overview. Transport still follows IETF RFC 5321 — Simple Mail Transfer Protocol.

email authentication: the real decision

Registrar tidy-From.

Chasing SPF by changing From.

Calling the rewrite SRS.

Criteria: Header From intact, exclusive MX, Authentication-Results, no self-send.

Rewrite versus SRS
ChangeDKIMDMARC
Envelope SRS onlyCan surviveAuthor DKIM can still align
Header From rewriteFails alignmentUsually fail
MIME mutateBody hash diesUsually fail
Exclusive leftover cutHop can runYou can read results

Prove inbound from another mailbox before you print hello@ on a homepage.

Start free — one domain

Technical mail flow for rewrite from breaks dkim dmarc

Author signed From: bank@…. Rewrite sets From: hello@you. DKIM d=bank no longer aligns. DMARC fails. Customer sees you. Replies miss the bank.

MailerZ path: From stays bank@…. SRS envelope. Gmail may still file spam. That is hop four, not a reason to rewrite.

Outbound send-as is your From on a new message. Do not mix the worksheets.

Leftover rewrite in series still wins if it accepts first.

MailerZ is inbound MX plus authenticated SMTP from Secuno LLC. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME are never rewritten. Not Google Workspace, not IMAP, not webmail, not an open relay. Unauthorized send is SMTP 550 / 550 5.7.1. Leftover MX is a hard stop. Self-send from Gmail to the same Gmail account can hide routing errors. Not SOC 2, not ISO 27001, not HIPAA.

SRS on envelope versus rewrite on header
Two RFCs. Panels that mix them are the bug.

deliverability

Prove From before you tune SPF includes.

  1. Look up MX. Delete rewrite leftovers.
  2. Publish exclusive MailerZ MX.
  3. Probe from another mailbox.
  4. Compare Header From to the author.
  5. Read dkim and dmarc.
  6. If From changed, you are still on a rewrite hop.
  7. Do not add the author to your SPF.
  8. Do not self-send.

Failure modes and proof

Tidy-From panel.

SPF chase rewrite.

Both MX live.

Self-send.

Weakened your DMARC to hide the rewrite.

Leftover MX is the usual ghost. Check a public lookup before you blame Gmail.

Open leftover MX troubleshooting

MailerZ workflow and product boundary

Header From never rewritten. Related: email forwarding, troubleshooting, tools, features.

Unauthorized send 550 / 550 5.7.1. Not an open relay.

Related pages: email forwarding, troubleshooting, tools, and features.

Customer replies to a fake From
Via lines and noreply loops start here.

forwarding authentication

p=reject bounces cost more than Solo. Confirm pricing. A suite will not fix a leftover rewrite hop in front.

Do not invent SOC 2 to win this argument.

MailerZ Free is one domain, three aliases, one seat, a 14-day store, send-as disabled, SMTP and API disabled, and unrouted mail held or rejected only. Solo is $40 per year only. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise.

Field notes you can reuse

Ask vendors which RFC they change.

Via lines are a clue, not the root.

Hold unknowns.

Agencies: per-zone exclusive MX.

Quarterly leftover review.

The DKIM article is the signature. This page is the From crime.

Preserve-sender is the inbound UX cousin.

Cite RFC 5321 for envelope, not as decoration.

Deeper field notes for rewrite from breaks dkim dmarc

Header From is the alignment name

Rewrite From breaks DKIM and DMARC because DMARC asks whether SPF or DKIM aligned with the domain in Header From. If you change Header From to your domain, the author’s DKIM no longer aligns (it signed a different From). Your SPF may pass for the hop and still fail DMARC if you did not DKIM as the new From. Most cheap “forwarders” rewrite From to look tidy and then wonder why banks bounce. MailerZ does not rewrite Header From. Envelope SRS only.

The via line and the spam button are cousins of this rewrite. Customers reply to a noreply you do not monitor. Authentication-Results look haunted. The fix is exclusive MX on an operator that leaves From alone, not a bigger SPF include list.

Why panels call rewrite “SRS”

SRS is an envelope technique. A visible From change is RFC 5322. If a registrar labels a From rewrite as SRS, walk. Ask which RFC they meant. Email authentication is hop-specific. Deliverability is the destination’s next job. Forwarding authentication is not an SLA.

When a rewrite is a different product

Privacy masks want a provider From. Suites send as the hosted user. Those are not inbound domain forwarding. If you need a mask, buy a mask and cite its docs. Do not run a mask policy on a business hello@ and expect bank DKIM to survive.

How to prove the rewrite

Probe from another mailbox. Compare Header From to the author you used. If From is now your domain or the forwarder’s domain, you have a rewrite hop. Move MX. Delete leftovers. Probe again. Do not add ~all theater. Do not self-send.

p=reject at the author plus a rewrite hop is a bounce machine. Keep the header. Let SRS handle the envelope. Read dkim and dmarc on the copy.

A complete worked story

The tidy panel and the rejected bank

A registrar rewrote From so Gmail “looked local.” The bank published p=reject. Invoices bounced. They cut MX to MailerZ, probed, and From was the bank again. DKIM passed. Gmail still filed one copy in Promotions. They left it. Rewriting would have bounced the rest.

Operator brief

A longer operator brief for rewrite from breaks dkim dmarc

Teams that bookmark Why Rewriting the Visible From Address Can Break DKIM and DMARC usually arrive after a missed invoice, a form that never notified anyone, or a migration that looked clean in one resolver. The useful brief is still boring. Name the store. Name the printed local-parts. Name the nameservers that actually answer. Publish one MailerZ MX set. Delete leftover hosts. Probe from a mailbox that is not the destination. Only then talk about rewrite from breaks dkim dmarc as a send-as, catch-all, or comparison problem.

MailerZ remains inbound MX plus authenticated SMTP around Gmail or Outlook. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. It is not a hosted mailbox, not IMAP, not webmail, and not an open relay. Unauthorized send is 550 / 550 5.7.1. Free cannot finish send-as: SMTP and API stay off. Solo is $40 per year when the domain From must travel. Starter is $8 or $80. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm the live pricing page. Those numbers are ceilings, not an inbox-placement service-level agreement.

If leftover Google, Microsoft, Cloudflare routing, or registrar MX is still public, stop widening rewrite from breaks dkim dmarc. The map you built never saw that copy. Priority numbers are an order, not load balancing. A higher preference host is idle while a leftover host still accepts mail. Save the old MX set before you delete anything. Check more than one public view because TTL lies.

Catch-all forward is not a safety feature for why rewriting the visible from address can break dkim and dmarc. Hold unknowns on everyday production. Review the store. Promote a leftover only when a real person used it. Paid forward belongs to a dated cutover. Fan-out of unknowns into two inboxes trains two spam buttons. Plus addressing on Gmail is not a custom-domain unknown policy. MailerZ will not strip plus tags on your domain the way Gmail does on @gmail.com.

Send-as is a second hop. Creating an inbound alias does not approve outbound. Catch-all does not mint a From. Copy the dashboard host, port, and TLS pair together. Set From to an identity you created. Do not paste a Gmail password into a CMS, a cron file, or a ticket. Do not mail SMTP secrets to support. Send a 550 line, a timestamp, and a Message-ID. Rotate if a secret already leaked.

Self-send from Gmail to the same Gmail account can short-circuit. That green result is why people swear rewrite from breaks dkim dmarc works while customers vanish. Use a second provider. Put a unique subject on the probe so delivery history is searchable. If Header From was rewritten by some other forwarder, authentication stories get noisier. MailerZ does not rewrite Header From on inbound.

Agencies should keep rewrite from breaks dkim dmarc per client zone. Separate SMTP credentials. Do not pour every client into one catch-all because the spreadsheet got long. Agency plan capacity exists so you can hold more domains and aliases. It does not replace a named list. Offboard means delete MX you own, revoke SMTP, and stop forwarding leftovers into the agency inbox.

Legal and security questions have published answers on the security, privacy, terms, DPA, and subprocessors pages. MailerZ is not SOC 2, not ISO 27001, and not HIPAA. The 14-day Free store, the 90-day Solo–Agency store, and the 180-day Unlimited store are recovery windows for hops this layer saw. They are not an archive and not legal hold. If counsel wants eDiscovery, buy eDiscovery.

Comparisons only help after the hop is honest. Cloudflare Email Routing is inbound routing. A privacy-mask product hides a destination on a provider domain. A suite hosts mailboxes, Calendar, and admin. Proton-class mailboxes encrypt a store. MailerZ is the delivery layer when you already have Gmail or Outlook and you need a domain route you can prove. Cite the other product’s documentation. Do not invent feature parity.

When Why Rewriting the Visible From Address Can Break DKIM and DMARC is closed, the next physical action is a lookup and a probe, not another tab. Start free on one domain you can break. Sign in if the zone already lives here. Review quarterly, or sooner after a nameserver move, a plugin swap, or a staff departure. That is how rewrite from breaks dkim dmarc stays a runbook instead of an incident.

A second worked pass for rewrite from breaks dkim dmarc: write the last change on a sticky note before you open the dashboard. Nameserver move, leftover MX, new form plugin, contractor laptop, or a registrar forwarding toggle are the usual five. MailerZ history only shows hops that reached this layer. If the sticky note says leftover MX, you do not have a rewrite from breaks dkim dmarc mystery. You have a split. Delete the leftover. Wait for TTL. Probe again.

A third worked pass: print the public list. If you cannot print it, you are not ready for production unknowns and you are not ready for a bigger alias ceiling. Unlimited aliases as marketing will not save a missing list. Three named aliases on Free are enough to stop printing a personal Gmail on a homepage. Grow the list when a real person used a leftover, not when a harvest guessed admin@.

More working detail

The sales sentence that causes the rewrite

“We’ll make it look like it came from you.” That sentence is how rewrite From breaks DKIM and DMARC gets sold as a feature. Inbound forwarding should look like it came from the author. Outbound send-as is the product that looks like you. Mixing them on the inbound hop is the bug. MailerZ splits them on purpose.

If a customer wants inbound to look like hello@yourdomain, they want a mailbox or a rewrite. Tell them the DMARC cost. If they want to send as hello@, sell paid SMTP. If they want to read the bank, leave From alone.

Security questionnaires that ask “do you rewrite From?” should get a written no for inbound. Point at the security page. Do not invent ARC magic to soften a yes you should not give.

Display-name tricks — keeping the bank’s name but changing the address — still change Header From’s domain. DMARC looks at the address domain. A pretty display name will not save alignment.

How to fire a rewrite leftover

Look up MX. If the rewrite host is still listed, delete it even if MailerZ is also listed. Preference is an order. A better-preference rewrite hop still wins. Exclusive. Probe. Compare From. Done.

One more working distinction

A reply loop you can draw

Author writes customer. Rewrite sets From to hello@you. Customer replies to hello@you. The author never sees it. Rewrite From breaks DKIM and DMARC and also breaks the conversation. Preservation is how replies find humans. That ops failure is enough even if you never read a DMARC XML file.

Support tickets should ask “who did the customer reply to?” If the answer is you and the thread was a vendor invoice, you rewrote. Open MX.

A short operating rule

SPF include as a false cure

After a rewrite, people add include:forwarder to the author’s SPF — which they do not control — or to their own. Neither restores the author’s DKIM alignment on a changed From. Rewrite From breaks DKIM and DMARC until From is restored. SPF theater will not. Delete the rewrite hop.

Ten-lookup limits make the theater worse. Count includes if you already stacked CRMs. Confirm dashboard SPF for send-as only.

Field close

p=none does not make rewrite safe

Authors on p=none still have users who filter on DKIM. Rewrite From breaks DKIM and DMARC alignment even when nobody bounces. Gmail still scores a noisier message. “Nobody rejects” is not a license to tidy From. Leave it. Exclusive MX.

Your own DMARC on send-as is a different worksheet. Do not weaken it because inbound rewrite taught you bad habits.

Last operating note

If marketing likes the tidy From, show one bounced p=reject and one lost reply. Rewrite From breaks DKIM and DMARC and the thread. Two artifacts beat a brand opinion. Then delete the leftover host.

If they want the brand in From, that is outbound send-as on a new message, paid. Different hop. Different RFC.

One last line

Ask the vendor to mark Header From on a whiteboard. If they mark it as changeable, walk. Rewrite From breaks DKIM and DMARC by definition. MailerZ marks it unchangeable. That is the buy, not a badge.

Then look up their leftover guidance. If they shrug, you will debug ghosts. Exclusive MX is part of the same no.

Close the gap

End the meeting with a probe, not a slide. Rewrite From breaks DKIM and DMARC until a third mailbox shows the author’s address. If the panel cannot survive that probe, it is not forwarding. It is a mask. Buy a mask on purpose or leave.

MailerZ will survive that probe when leftovers are gone. Start free on a domain you can break.

Final distinction

If legal asks whether you alter sender identity, the inbound answer is no. Rewrite From breaks DKIM and DMARC and also breaks that answer. Point at the security page. Do not invent a certification to soften a rewrite you should not do.

Three checks

Exclusive MX. Intact From. Third mailbox. Those three end rewrite From breaks DKIM and DMARC as a mystery. Everything else is a different hop.

Then stop

If those three checks pass, stop rewriting. If they fail, look up MX. Rewrite From breaks DKIM and DMARC is then a leftover, not a theory.

FAQ

What is the safest way to handle rewrite from breaks dkim dmarc?
Do not change Header From on inbound. DMARC aligns to that field. Use exclusive MX on a hop that leaves From intact, probe from another mailbox, and read dkim and dmarc. Envelope SRS is not a From rewrite.
Does this require a new mailbox?
No. MailerZ is not IMAP and not webmail. Gmail or Outlook remains the store unless you separately buy a hosted mailbox product.
Will it work with Gmail or Outlook?
Yes for inbound when the destination is a verified mailbox. Branded replies need paid send-as plus Gmail Send mail as or a manual Outlook SMTP identity. Free has no send-as.
What DNS records are involved?
A verification TXT, one MailerZ MX set on the authoritative nameservers, leftover host MX removed, and SPF, DKIM, and DMARC if you also send as the domain.
What should I test before production?
Send a uniquely titled message from an unrelated provider into each named alias. Confirm Header From and delivery history. Do not email yourself from the same Gmail account.

Key takeaways

  • DMARC uses Header From.
  • Rewrite kills alignment.
  • SRS is envelope.
  • Exclusive MX.
  • Read the copy.
  • No SPF chase.
  • p=reject + rewrite = bounce.
  • Not an inbox SLA.

Conclusion and next action

Rewriting the visible From breaks DKIM alignment and DMARC. Leave From alone. Let SRS handle the envelope. MailerZ is built that way. Cut leftover rewrite hops.

Start free. Sign in if From already changed and the registrar still answers.

Leave From alone

Start free on an operator that does not rewrite Header From.

If a panel changes From, keep shopping.

Review quarterly, or sooner if Gmail, Workspace, or MailerZ scope changes. Author: MailerZ editorial, Secuno LLC.