Fix guide
How to Fix DMARC Alignment for Proofpoint
Running Proofpoint in front of mail? Match their DKIM/signing settings to your From: domain and keep SPF honest — this page is the checklist.
Why Proofpoint + DMARC gets messy
Gateways rewrite paths — keep DKIM d= and SPF consistent with what you actually send, or alignment flakes under policy.
Exact DNS records
Step-by-step fix
Run your domain through DNS Preflight
Open DNS Preflight →FAQ
Gateway vs relay — how does alignment differ?
Relays change which IP and envelope domain receivers see. Work with Proofpoint documentation for your deployment so SPF and DKIM d= align with From:.
How do I enable DKIM in Proofpoint?
Use the admin console for your Proofpoint product to generate keys and publish DNS TXT records at the given selectors.
How does SPF alignment work with relays?
Return-Path and sending IP must match your SPF design; complex relays may need SRS or aligned bounce domains — consult Proofpoint support.
Why is Proofpoint alignment complex?
Enterprise mail paths often involve multiple hops and gateways — alignment must be validated end-to-end.
How do I verify alignment?
Inspect headers on test messages, use DMARC reports, and DNS Preflight for published DNS.