What ARC (Authenticated Received Chain) is#
ARC preserves authentication results across intermediaries such as mailing lists and forwarders. Each hop signs the results it saw, so the final receiver can trust an earlier pass even if SPF or DKIM broke in transit.
Why it matters#
Forwarding and mailing lists are the largest source of legitimate DMARC failures. ARC lets receivers accept mail that would otherwise be quarantined under p=reject.
How mailbox providers use it#
Gmail, Microsoft, and Yahoo combine authentication results, sender reputation, and recipient engagement into a placement decision made per message. ARC (Authenticated Received Chain) feeds directly into that model, and weaknesses compound with other signals.
How to measure the impact#
- Baseline inbox placement with seed tests before any change.
- Make one change at a time and hold volume steady.
- Re-test after 48 to 72 hours; provider models need time to update.
- Track Postmaster Tools and SNDS alongside your seed results.
Improving it#
- Check whether your inbound gateway or mailing-list software supports ARC sealing.
- Enable ARC sealing on any system that modifies and re-sends mail.
- Verify ARC-Seal, ARC-Message-Signature, and ARC-Authentication-Results headers appear on forwarded mail.
- Confirm downstream receivers (Gmail, Microsoft) honor your seals by checking Authentication-Results for arc=pass.
Frequently asked questions#
Do I need ARC as a sender?
No. ARC is implemented by intermediaries and receivers. Senders benefit indirectly when their mail is forwarded.
Which providers honor ARC?
Gmail, Microsoft, and Yahoo all evaluate ARC when deciding whether to override a DMARC failure.