Skip to content
Solutions Blueprint

Relaxed DMARC Alignment Unblocks a New Sending Subdomain

Hero featured image

A root domain's existing DMARC record used strict alignment, and it would have blocked HubSpot's sends outright once a new sending subdomain went live. We scoped a dedicated subdomain with its own SPF and DKIM, relaxed the root domain's DMARC alignment to permit it, and cleared the subdomain through the client's corporate security filters before any mail moved through it.

Executive Summary

context-header-icon

Context

A B2B events and exhibitions operator running 90+ annual conferences across 35 brands needed a new sending subdomain live ahead of a HubSpot migration, and its DMARC posture was built around years of unrelated corporate mail, not a fresh third-party sender.

what-we-built-header-icon

What We Built

We split domain authentication in two: SPF and DKIM scoped to a new dedicated subdomain, and a relaxed DMARC alignment mode at the root that let HubSpot's sends pass without loosening protection for existing mail.

tech-stack-header-icon

Tech Stack

  • HubSpot Marketing Hub
  • DNS (SPF, DKIM, DMARC)

Not a fit if your organisation doesn't control its own domain's DNS zone, since relaxing DMARC alignment and scoping new SPF and DKIM records both require direct authority over those records. It also assumes an IT function willing to allowlist a new subdomain in corporate mail filters ahead of go-live, since without that step the sender won't reliably reach inboxes.

the-challenge-header-icon

The Challenge

The client's root domain carried years of unrelated corporate mail under a DMARC record set to strict alignment, which ties a message's visible From address to the domain that signed it. HubSpot's sending infrastructure couldn't produce that exact match from a brand-new subdomain, so the policy would have rejected the sends the moment they went live.

Loosening the root policy without limit risked weakening authentication for mail that already relied on strict alignment, so the fix had to isolate the new sender rather than relax protection domain-wide. The client's own corporate security filters added a second constraint. They flag unfamiliar infrastructure by default, and they can quarantine mail before a recipient sees it.

our-approach-header-icon

Our Approach

We considered adding the subdomain to the root domain's existing SPF record and leaving DMARC at strict alignment, because it was the simplest option and needed no new DNS zone. It hit the same wall the policy enforces: HubSpot's infrastructure couldn't authenticate as an exact match to the root domain, so strict alignment would still have rejected it.

We built a dedicated sending subdomain instead, with its own SPF and DKIM records, and moved the root domain's DMARC policy to a relaxed mode, adkim=r and aspf=r, so that the subdomain's authentication could satisfy it. That change had to land before any send volume moved, because a misconfigured record fails mail silently.

We also worked with the client's own IT function to allowlist the subdomain ahead of warm-up. That traded a stricter default posture for a named, approved exception.

impact-header-icon

Impact

check-icon

A new subdomain authenticates without touching existing mail

Scoping SPF and DKIM to the new subdomain gave HubSpot's sends their own signature and their own SPF pass, so the client's established corporate mail kept its original protections untouched.

check-icon

A relaxed root DMARC policy clears the alignment HubSpot needed

Moving the root domain's DMARC alignment to a relaxed mode let a message the subdomain signs count as aligned with the parent domain, which is what HubSpot needed to deliver at all.

check-icon

Corporate security filters recognise the subdomain before any send goes out

Coordinating the allowlist with the client's own IT function cleared the subdomain through corporate mail-security review before warm-up began, rather than risking a quarantine once real volume started moving.

check-icon

Authentication finished as a precondition, not a parallel task

The subdomain's SPF and DKIM, the relaxed root DMARC alignment, and the corporate allowlist were all in place before the send-volume ramp began, so the first messages arrived already authenticated.

Technical Blueprint
1

A newly created subdomain of the client's root domain, provisioned to originate HubSpot's marketing sends and kept separate from the root domain's own mailboxes. Every authentication change that followed could be scoped there alone.

2

The subdomain carries its own SPF record authorising HubSpot's sending infrastructure and its own DKIM key pair, rather than inheriting either from the root domain, so HubSpot's sends authenticate on their own terms.

3

The root domain's DMARC record moved from strict alignment to a relaxed mode, adkim=r for DKIM and aspf=r for SPF, so a message the subdomain signs still counts as aligned with the parent domain.

4

Subscription-preference pages that HubSpot's sends link to were hosted on a domain distinct from both the root domain and the sending subdomain, keeping the reputation the warm-up was protecting isolated from those pages.

Diagram of a dedicated sending subdomain with its own SPF and DKIM, inheriting a relaxed root DMARC policy that authenticates HubSpot's mail.

HubSpot sends mail through a new subdomain that has its own SPF record and its own DKIM key. The root domain's DMARC policy, now set to relaxed alignment with adkim=r and aspf=r, evaluates both and counts the subdomain's messages as aligned, where the old strict policy would have blocked them. Before sending starts, the subdomain is also allowlisted in the client's corporate mail filter.

FAQ

Why would an existing DMARC record block mail from a brand-new subdomain?

Strict DMARC alignment requires a message's visible From address to match, character for character, the domain that signed it with SPF or DKIM. A brand-new subdomain using different infrastructure can't produce that match, so the owner must relax the alignment mode or give it matching authentication, or the message gets rejected or marked as spam.

Does relaxing DMARC alignment weaken protection for the rest of a domain's mail?

Not when it's scoped correctly. Relaxed alignment still requires SPF or DKIM to pass, and it only widens which subdomains count as a match. Pairing that root-level change with SPF and DKIM records scoped to the new subdomain means the new sender authenticates on its own credentials, so the existing mail keeps the protection it had before.

Continue reading

Hero featured image
209049082793

Luxury yacht manufacturer: CRM governance, 16.9% MQL-to-SQL

Hero featured image
209049052783

$500M+ telecom provider: one CPQ for MSP and ISP catalogs

Hero featured image
209049052785

Health insurance web broker: NPN hierarchies in HubSpot

Hero featured image
209049052787

$50M+ telehealth provider: HIPAA-compliant clinical ERP sync

Hero featured image
209049052787

$50M+ telehealth provider: attribution recovered via API fix

Hero featured image
209049052786

Environmental IoT provider: partner directory routes leads

Hero featured image
209053190299

$100M+ real estate tech firm: automated KYC gates and SSO

Hero featured image
209049052785

$1B+ financial data provider: Pardot and Eloqua into HubSpot

Hero featured image
209053177394

Global abrasives producer: 40+ sites from Kentico to HubSpot

Hero featured image
209049082792

Global abrasives producer: 13 dashboards consolidated to one

Hero featured image
209049052787

Medical device maker: five regional domains into one CMS

Hero featured image
209049052787

Medical device maker: automated clinical triage in HubSpot

Hero featured image
209049052787

Multi-site dental group: lifecycle logic rebuilt, true ROI

Hero featured image
209049052787

Multi-site dental group: assessment tool for lead quality

Hero featured image
209049082794

K-12 Catholic diocese: 80 schools on one HubDB lead system

Hero featured image
209049052787

Cell therapy biotech: HubSpot CMS migration, 92 speed score

Hero featured image
209049052787

Cell therapy biotech: 40-hour enablement and lead routing

Hero featured image
209049082794

Wellness training provider: 925k records moved to HubSpot

Hero featured image
209049052786

Cybersecurity trainer: 595 workflows audited for debt

Hero featured image
209049052785

Tier 1 auto F&I provider: 14,000% CTA lift, 21% PVR lift

Hero featured image
209049052785

Mexican retail bank: Infobip to Intercom via Apache NiFi

Hero featured image
209049052786

Global streaming platform: ETL middleware feeds Customer.io

Hero featured image
209049052786

Global streaming platform: usage milestones trigger upsell

Hero featured image
209049052786

Cloud and edge provider: Intercom to Salesforce via MuleSoft

Hero featured image
209049052785

$50M+ FinTech SaaS provider: advisor onboarding 30% faster

Hero featured image
209049082792

Mining autonomy provider: global consent and data governance

Hero featured image
209053177394

Industrial IoT division: compliant list purge, leads 3 to 62

Hero featured image
209053177394

Industrial IoT division: 25,000 records merged, one portal

Hero featured image
209049052786

Logistics SaaS portfolio: Salesforce sync rebuilt on Tray.io

Hero featured image
209049052786

Logistics SaaS portfolio: brands consolidated into HubSpot

footerCTA footerCTA-mobile
Spice up your inbox
Sign up for our newsletter
Don't worry - we only average, like, two emojis per subject line.