How does DMARC work with domains and subdomains in email addresses?
DMARC stores data specifying how email recipients should verify incoming messages for authenticity using the Domain Name System (DNS). However, how receivers use DMARC when subdomains are involved is one of the lesser understood parts of DMARC. While it may appear straightforward at first, the behavior may get complex. There are a few critical aspects to grasp while dealing with subdomains. In this article, we'll look at the first issue, which is how the DMARC policy records are queried. In other words, which DNS TXT entries are checked by receivers? Basic rules of email transmission and DMARC
Receivers look for DMARC records based on the domain in the RFC5322 From address, also known as the 'From' address. Receivers will only perform one or two DNS requests to find a DMARC record for a message.