Skip to content

Home Topics Email Authentication ARC

Email Authentication · ARC

2 common ARC (Authenticated Received Chain) mistakes and how to fix them

Short answer

The most common ARC (Authenticated Received Chain) mistakes are: expecting ARC to fix your own outbound authentication; it only helps intermediaries; trusting ARC from unknown sealers, which reopens the spoofing door.

Forwarding and mailing lists are the largest source of legitimate DMARC failures. ARC lets receivers accept mail that would otherwise be quarantined under p=reject.

Mistake 1: Expecting ARC to fix your own outbound authentication; it only helps intermediaries#

Why it hurts: this undermines ARC (Authenticated Received Chain) at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.

Fix: Check whether your inbound gateway or mailing-list software supports ARC sealing.

Mistake 2: Trusting ARC from unknown sealers, which reopens the spoofing door#

Why it hurts: this undermines ARC (Authenticated Received Chain) at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.

Fix: Enable ARC sealing on any system that modifies and re-sends mail.

Frequently asked questions#

Do I need ARC as a sender?

No. ARC is implemented by intermediaries and receivers. Senders benefit indirectly when their mail is forwarded.

Which providers honor ARC?

Gmail, Microsoft, and Yahoo all evaluate ARC when deciding whether to override a DMARC failure.

Analyse your own setup

All analysers
Technical analysis

SPF record analyser

Parse an SPF record, count its DNS lookups, and find what will break it.

Runs in your browser
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser
Technical analysis

DKIM key analyser

Check a DKIM public key's strength, revocation state, and tags.

Runs in your browser

Keep reading on ARC