Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

What is

What is ARC

ARC is an experimental protocol in RFC 8617 that lets each intermediary add a signed chain showing how SPF, DKIM, and DMARC evaluated at that hop. A mailbox provider can use the chain when forwarding breaks alignment on the original From domain.

ARC adds three header fields: ARC-Authentication-Results, ARC-Message-Signature, and ARC-Seal. Each hop seals the previous chain so a verifier can detect tampering.

Why forwarding broke DMARC

Mailing lists and forwarders often change the envelope address or add their own DKIM signature. DMARC alignment for the original From domain can fail even when the forwarder is legitimate. RFC 8617 documents a chain format so downstream verifiers can see earlier authentication results.

ARC does not replace DMARC. It preserves evidence. A receiver still applies its own policy, but it can consult the chain when deciding whether a broken alignment is explained by forwarding.