Skip to content

Home Topics Email Authentication ARC

Email Authentication · ARC

ARC (Authenticated Received Chain) checklist for 2026

Short answer

A complete ARC (Authenticated Received Chain) checklist has 4 setup items and 2 things to audit against. Work through setup in order, then schedule a quarterly review.

Setup checklist#

  • ☐ Check whether your inbound gateway or mailing-list software supports ARC sealing.
  • ☐ Enable ARC sealing on any system that modifies and re-sends mail.
  • ☐ Verify ARC-Seal, ARC-Message-Signature, and ARC-Authentication-Results headers appear on forwarded mail.
  • ☐ Confirm downstream receivers (Gmail, Microsoft) honor your seals by checking Authentication-Results for arc=pass.

Audit checklist#

  • ☐ Confirm you are not: expecting ARC to fix your own outbound authentication; it only helps intermediaries.
  • ☐ Confirm you are not: trusting ARC from unknown sealers, which reopens the spoofing door.

Ongoing monitoring#

  • ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
  • ☐ Monthly: re-run the setup verification after any vendor or DNS change
  • ☐ Quarterly: full audit against this checklist

Frequently asked questions#

Do I need ARC as a sender?

No. ARC is implemented by intermediaries and receivers. Senders benefit indirectly when their mail is forwarded.

Which providers honor ARC?

Gmail, Microsoft, and Yahoo all evaluate ARC when deciding whether to override a DMARC failure.

Analyse your own setup

All analysers
Technical analysis

SPF record analyser

Parse an SPF record, count its DNS lookups, and find what will break it.

Runs in your browser
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser
Technical analysis

DKIM key analyser

Check a DKIM public key's strength, revocation state, and tags.

Runs in your browser

Keep reading on ARC