Building Trust in Multi-Tenant SMTP Relays via MAIL FROM Domain Auth
Ensure your multi-tenant SMTP relay delivers with trust. Learn how MAIL FROM domain authentication prevents spoofing and boosts inbox placement.
Why Does Multi-Tenant SMTP Relaying Undermine Sender Trust?
You send a campaign. It lands in the spam folder. Not because your content is poor—but because the SMTP relay you used served a malicious sender earlier today, and the domain you’re using was left unauthenticated.
That’s the risk of multi-tenant SMTP relays. The same infrastructure used by thousands of senders means one bad actor can tank inbox placement for everyone sharing the same domain or IP. Without hard checks on who’s allowed to send from which MAIL FROM domain, reputation damage spreads fast.
Trust in email delivery starts not with content or frequency—but with domain authentication. When SPF, DKIM, and DMARC are weak or ignored, attackers can forge the MAIL FROM domain and hijack sender reputation. The result? Inbox placement drops, even for clean senders.
Key takeaways
- Multi-tenant SMTP relays expose all senders to reputational risk when one uses the same MAIL FROM domain or IP without strict domain authentication.
- Forgeable MAIL FROM domains allow attackers to impersonate senders, triggering spam filters and blocking legitimate emails even when content is safe.
- Enforcing MAIL FROM domain authentication with SPF, DKIM, and DMARC is non-negotiable for maintaining sender trust in shared email infrastructure.
What Is MAIL FROM Domain Authentication, and Why It Matters
The MAIL FROM domain is the technical sender address in an email’s SMTP envelope — the origin the receiving server uses to evaluate authenticity, reputation, and spam risk. If it’s not properly authenticated via SPF, DKIM, or DMARC, the email is treated as unverified, even if your content is perfect and your list is clean. Authenticating this domain ensures only authorized senders can use it, preventing spoofing and protecting your sender reputation.
The Technical Role of MAIL FROM
When an email is sent, the SMTP protocol uses two key addresses: the MAIL FROM (envelope sender) and the From: header (display sender). The MAIL FROM is the one that matters for delivery decisions. Receiving servers check this address against your domain’s DNS records to verify authorization. Without proper configuration, your message is flagged as potentially suspicious — often rejected before it even reaches inbox filters.
Let’s be clear: if your MAIL FROM domain isn’t authenticated, you’re sending emails with an unverified origin. That’s like showing up to a meeting without ID — the door may not open. This isn’t about content quality or list hygiene. It’s about proving you’re who you claim to be at the protocol level.
Authentication via SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting & Conformance) creates a layered defense. SPF specifies which IPs can send on your behalf. DKIM signs the email content cryptographically. DMARC tells receiving servers what to do if either check fails.
Why It’s Crucial for Multi-Tenant SMTP Relays
In multi-tenant environments — where one SMTP relay serves many senders using different domains — MAIL FROM authentication is not optional. Without it, any tenant can impersonate another domain, making it easy for spammers to abuse the relay. This damages the entire shared infrastructure’s reputation.
Reputable email services and inbox providers like Gmail, Outlook, and Yahoo depend on these checks to filter spam. A single unauthenticated MAIL FROM domain can hurt delivery for every sender using the same relay. That’s why modern systems enforce strict alignment between the MAIL FROM domain and your authentication records.
You can test your authentication setup with tools like MxToolbox or by checking RFC 5321, which defines the SMTP MAIL FROM command. For deeper validation, it’s practical to audit your full email infrastructure with real-time verification. Tools like bulk email list verification help confirm that your domains and sending IPs are properly aligned and deliverable, reducing bounce rates and protecting your sender reputation over time.
How SPF, DKIM, and DMARC Work Together to Secure MAIL FROM
You authenticate your MAIL FROM domain using SPF, DKIM, and DMARC together because no single protocol covers all threats. SPF checks if the sending IP is authorized. DKIM verifies the message wasn’t altered. DMARC combines both results, applies policies, and reports failures — giving you control and visibility. When one fails, the others can still provide insight. This trio is how email providers distinguish trusted senders from impersonators.
How Each Layer Protects Your Mail Flow
Let’s break down why each protocol matters in the authentication chain.
| Protocol | What It Validates | How It Works | Limitations |
|---|---|---|---|
| SPF | Sender IP authorization | Checks if the sending IP appears in the domain’s published SPF record in DNS | Only validates the envelope sender (MAIL FROM), not the visible From: header. Can’t handle forwarded messages. |
| DKIM | Message integrity and origin | Digitally signs parts of the email (headers and body). Receivers verify the signature using the sender's public key in DNS | Doesn’t validate sender identity alone. Signatures are broken if headers are altered by relays or forwarding services. |
| DMARC | Policy enforcement and reporting | Uses SPF and DKIM results to decide whether to accept, quarantine, or reject a message. Sends aggregate and forensic feedback to the domain owner | Relies on correct SPF and DKIM setup. If either fails, DMARC can still enforce policy, but reporting depends on sender cooperation. |
DMARC is the only protocol that acts as an enforcement layer. Without it, even if SPF and DKIM are configured, receivers lack a clear instruction on what to do with failing messages.
Why This Matters for Multi-Tenant SMTP Relays
When you use a shared SMTP relay, multiple tenants send from your domain. Without strict MAIL FROM domain authentication, attackers could impersonate any tenant — especially if the relay doesn’t validate sender identity at the envelope level. SPF alone isn't enough if you’re not managing IP lists carefully across tenants. DKIM ensures the content you send isn’t tampered with, which is critical if your relay forwards messages through third-party systems. DMARC reports show who’s sending, and how often. You can use those reports to detect anomalies or unauthorized senders.
Together, these protocols form a defense in depth. They don’t stop all spam, but they make your domain significantly harder to spoof — a key factor in inbox placement. Email providers like Gmail, Microsoft, and Apple use DMARC enforcement signals to decide whether to route your message to the inbox or spam folder.
If you're managing a multi-tenant system or sending at scale, validating sender identity upfront is non-negotiable. You can test your setup with tools from inbox placement testers or verify your domain’s status with bulk verification tools that check deliverability signals. For real-time enforcement, use the email verification API to validate sender domains before sending.
For deeper guidance, refer to the official RFCs: SPF, DKIM, and DMARC. They define the standards that power modern email trust.
The Risk of Shared Infrastructure Without MAIL FROM Isolation
When multiple tenants share the same SMTP relay, a single misconfigured or compromised sender can break DMARC for every domain using that relay. Receiving servers see the same MAIL FROM domain and IP address — if one fails authentication, the entire domain may be flagged, quarantined, or blocked, even if other senders are clean. This exposes all users to deliverability risk simply because they’re on the same infrastructure.
How a Single Failure Propagates Across Domains
Let’s say your company sends newsletters through a shared relay. Another tenant on the same system uses a spoofed MAIL FROM domain or has poor authentication setup. The receiving email provider sees that the MAIL FROM domain doesn’t align with SPF or DKIM, and the IP has a poor reputation. Even if your own setup is perfect, DMARC can still fail because the domain reputation is tainted by the shared IP and sender identity.
This isn’t hypothetical — it’s a documented behavior in email authentication. The DMARC specification explicitly allows receivers to reject messages when alignment fails, and they often treat the MAIL FROM domain as a single entity across all senders sharing that infrastructure. A bad actor or mistake by one user can trigger blanket filtering.
Why Isolation Matters for Sender Reputation
Shared infrastructure removes the ability to isolate reputational risk. A single spam campaign or credential leak can damage every sender using the same relay. This is especially risky for multi-tenant platforms like email marketing services, SaaS providers, or agencies managing multiple brands. Without MAIL FROM isolation, you’re effectively sharing a single digital fingerprint — and that fingerprint can be compromised at any point.
Even if you’re using a reputable platform, if it doesn’t enforce MAIL FROM domain separation and enforce authenticator alignment per sender, your deliverability is never truly under your control. The risk is not just technical — it’s financial. A sudden spike in bounces, blocks, or quarantines can impact conversion, customer trust, and revenue.
If you're verifying or managing large email lists, ensure you’re not relying on shared relays without domain-level authentication controls. You can validate the health of your sender identity and catch issues early with tools like bulk email verification — which checks for invalid, disposable, or catch-all addresses before they hurt your reputation.
Real-World Consequences of Unverified MAIL FROM Domains
You don’t need to be a security expert to see the damage: when MAIL FROM domains aren’t properly authenticated, your emails either vanish into spam folders or get blocked entirely—no clear error, no warning, just silence. This isn’t just unreliable delivery; it’s a systemic risk that can trigger blocklisting, ruin sender reputation, and take months to fix, even after the original problem is corrected.
Delivery Failure Without Feedback
Let’s be clear: if your MAIL FROM domain isn’t verified, your messages can fail silently. The recipient server sees a mismatch or lacks proof of legitimacy and drops the email into spam or rejects it outright. No bounce report. No alert. No clue. This is especially dangerous in multi-tenant setups where one misconfigured tenant can degrade delivery for dozens of others. You might assume your message was sent, but it never reached the inbox.
Spam Traps and Permanent Blocklisting
Forged or unverified MAIL FROM domains are a magnet for spam traps. When multiple clients use the same unauthenticated domain across different campaigns, the same address can get flagged as a trap—especially if the domain was once used for disposable or test emails. Once those traps are triggered, ISPs like Google and Yahoo mark the domain as high-risk. And once a domain is blacklisted, it’s not just a temporary penalty: removal from a major blocklist like Spamhaus can take weeks, sometimes months, especially if the issue is traced back through multiple tenants using shared relays.
Even after you fix the misconfiguration, the domain’s reputation remains damaged. ISPs assess sender reputation based on historical behavior, and a single instance of spam trap hitting can lead to persistent inbox filtering. The recovery process often requires proving clean sending behavior over a sustained period. That’s why you don’t just lose one email—you risk losing all trust in the domain.
Authentication isn’t optional. It’s how you prove your domain is not a forgery. SPF, DKIM, and DMARC aren’t just technical checkboxes—they’re the foundation of deliverability. Without them, your messages are treated as suspicious by default. Even if you’re sending legitimate content, the absence of authentication is enough to send you to the spam folder.
That’s why you need to validate every MAIL FROM domain you use. The cost of a failed delivery is high—not just in lost engagement, but in damaged credibility. Use tools that verify both syntax and legitimacy before you send. Check if you’re using a catch-all, if the domain is blacklisted, or if it’s known to be disposable. A simple verification step can protect your domain’s reputation and your message’s reach.
Our bulk verification tool checks for these issues in real time, including domain reputation, catch-all status, and mailbox health—so you know exactly what can and cannot be trusted before your first send.
How to Secure MAIL FROM Authentication in Multi-Tenant Environments
You secure MAIL FROM authentication in multi-tenant SMTP relays by enforcing unique SPF records per domain, signing every email with a domain-specific DKIM key, and monitoring DMARC policies independently for each client. This prevents shared infrastructure from undermining deliverability and trust. Without this, even valid emails risk bouncing or landing in spam.
SPF: Prevent Shared IP Abuse
- Never use a single IP range for multiple MAIL FROM domains — each client must have a distinct SPF record.
- Explicitly list the authorized sending IPs for each domain using
includeorip4mechanisms to avoid over-permissive wildcards. - Use RFC 7208 as a reference for proper SPF syntax and deployment — shared IP ranges are a common cause of authentication failures in shared environments.
DKIM: Per-Domain Signing Is Non-Negotiable
- Assign a unique DKIM key pair to each domain — never reuse keys across tenants.
- Validate DKIM signatures at the receiving end independently per domain; shared keys can expose all clients to a single compromise.
- Ensure public keys are published via DNS with the correct selector and domain alignment — tools like MxToolbox can verify DNS publishing.
DMARC: Monitor, Don’t Overblock
- Implement DMARC with policy enforcement set to
noneinitially across all domains to observe reports without disrupting mail flow. - Review DMARC aggregate reports (RUA) per domain to detect unauthorized senders, then adjust policies incrementally.
- Avoid overly aggressive policies like
p=rejectwithout testing — a misconfigured DMARC can block legitimate mail from trusted sources.
For teams handling bulk email lists, you can audit your current MAIL FROM domain setup using real-time verification tools that validate SPF, DKIM, and DMARC during the verification process. Try bulk verification to test your entire list and catch domain-level authentication flaws before sending.
Why Your Email List Matters When Authenticating MAIL FROM
Even with perfect MAIL FROM domain authentication, a poor-quality email list can still sink your deliverability. Spam filters don't just look at headers—they watch for red flags like sudden spikes in volume, high bounce rates, or engagement with disposable, role, or catch-all addresses. Authenticating the domain is necessary but not enough. You need a clean, valid list to maintain sender reputation and landing in the inbox.
Authentication Isn't a Pass for Bad Lists
SPF, DKIM, and DMARC secure the MAIL FROM domain, but they don’t guarantee inbox placement. A high bounce rate—especially from disposable or role accounts—signals to inbox providers that your list may be compromised or purchased. According to a study by Return Path, sender reputation is degraded by consistent high bounces, even if authentication is correct. This means a technically compliant email can still end up in spam.
Imagine sending 10,000 messages from a verified domain, but 30% bounce because they’re from [email protected] or [email protected]. That’s not just low engagement—it’s abuse behavior. Providers like Gmail and Outlook use machine learning to detect volume anomalies. A sudden burst in sends from a single domain, even if authenticated, can trigger filters if the list is noisy.
Quality Starts with Pre-Send Validation
Let’s be honest: not every email on your list is real. Some are outdated, misspelled, or intentionally fake. These addresses don’t reply, so they don’t improve engagement—but they still count as outbound attempts. That’s why validating every address before sending is non-negotiable.
Use tools that test for syntax, domain existence, mailbox reachability, and role/catch-all patterns. Real-time verifiers can tell you if an email is valid, a catch-all, disposable, or risky—before you send. This means fewer bounces, better sender reputation, and higher inbox placement.
For teams using SendGrid, Mailchimp, HubSpot, or Klaviyo, integrating with a trusted verifier like Emaillistchecker’s verified email integrations allows you to clean your list automatically before campaigns launch. With bulk verification available at https://www.emaillistchecker.io/bulk-verification, you can process 500K+ addresses at once with 98.9% accuracy—ensuring only valid, responsive recipients receive your message.
Ultimately, MAIL FROM authentication is a baseline. Deliverability depends on what you do with that foundation. Clean lists, consistent volume, and real engagement—not just technical correctness—are what build trust with inbox providers.
How Email Verification Reinforces MAIL FROM Domain Trust
Verifying emails before sending is how you build trust in your MAIL FROM domain. By filtering out invalid addresses, role accounts, and disposable domains, you reduce bounces and spam complaints—both of which directly harm sender reputation. This ensures only deliverable emails are sent, aligning with industry standards for responsible email practices.
Pre-Send Validation Prevents Reputation Damage
Every invalid address in your send list is a potential red flag to inbox providers. A single bounce or complaint can trigger filtering, especially if it's part of a larger pattern. You reduce that risk by catching issues before sending—like malformed addresses, role accounts (e.g., admin@, sales@), or temporary disposable domains.
Let’s be clear: sending to a role account isn’t just ineffective—it’s risky. These addresses often trigger inbox filters or generate spam complaints when users ignore bulk emails. A service like bulk email verification screens for those red flags at scale, so you avoid them entirely.
Accuracy Matters for Sustained Deliverability
High accuracy means fewer false negatives and fewer false positives. With 98.9% accuracy, EmailListChecker.io ensures you’re not losing valid contacts while filtering out harmful ones. That level of precision is critical when you're managing large lists across multiple tenants or clients, where even small error rates add up.
Real-time API verification is how you maintain trust in dynamic environments—automatically checking addresses as they’re added, not waiting for delivery failures. Whether you're syncing with Mailchimp, HubSpot, Klaviyo, or SendGrid via our integrations, you’re verifying at the point of entry.
Think of it as sending only to verified endpoints. That’s how you signal to email providers that your MAIL FROM domain is clean, consistent, and trustworthy. This isn’t about shortcuts—it’s about aligning your sending behavior with DNS-level protocols like SPF, DKIM, and DMARC, which all depend on valid, deliverable mail flow.
For deep testing, inbox placement reports simulate real delivery across inboxes and spam folders. These tests validate not just delivery, but how your messages are treated—important for verifying that domain trust is translating into actual inbox visibility.
Integrating Verification into Your SMTP Workflow for Better Deliverability
Validating every email before sending through a multi-tenant relay isn’t optional—it’s how you prevent bounces, reduce spam complaints, and protect your sender reputation. By automating checks and aligning them with domain authentication, you build a delivery foundation that works across shared infrastructure.
- Verify every address before sending via the Emaillistchecker.io APIIntegrate the real-time verification API into your pre-send workflow. It checks syntax, domain validity, and inbox existence in under 500ms per address. This catches typos, invalid domains, and non-existent users before they hit your relay, directly reducing hard bounces and improving inbox placement.
- Run inbox-placement tests on high-value segmentsUse inbox-placement testing on key segments—like new subscribers or high-value campaigns—to catch delivery risks before your full send. This reveals whether messages land in spam folders or fail outright, especially under real-world conditions across Gmail, Outlook, and Apple Mail. Early detection prevents reputation damage.
- Pair verification with MAIL FROM domain authenticationEnsure your MAIL FROM domain matches your sending domain and supports SPF, DKIM, and DMARC. Verification results show whether a domain accepts mail, but authentication confirms it’s authorized. A mismatch here increases the risk of rejection—even with a valid address. Use verified data to validate config alignment.
- Monitor sender reputation with behavior trackingCombine verified lists with domain policy enforcement and monitor engagement patterns. High spam complaints or low open rates degrade sender reputation, even with correct authentication. Tools like integrations with SendGrid, Mailchimp help track delivery outcomes over time and flag anomalies.
Why This Works in Multi-Tenant Environments
In a shared SMTP relay, your reputation can be dragged down by others. But when you verify each address and confirm your domain policies are enforced, you isolate your risk. Even if another sender’s list contains errors, your clean, authenticated mail continues to deliver. This is how you maintain trust—even in crowded infrastructure.
Think of it as a firewall: you don’t stop all traffic, but you filter out the noise. The SMTP relay handles the transport; your verification layer ensures only credible, engaged addresses get through. This isn’t just about fewer bounces—it’s about sustainable delivery in shared systems.
Authentication alone doesn’t guarantee inbox placement. But paired with address validation and sender behavior monitoring, it becomes a cornerstone of consistent, trusted delivery.
Standards like RFC 5321 and RFC 6376 define how mail systems should behave; following them is necessary, but not sufficient. You must also control your input and output at scale. That’s where automation and verification meet real-world deliverability.
MAIL FROM Authentication Is Not a One-Off Setup — It’s an Ongoing Process
Authenticating your MAIL FROM domain isn’t a checkbox you check once and forget. It requires continuous validation, especially after changes to your email infrastructure, domain ownership, or IP addresses. Even small shifts can break alignment between your SPF, DKIM, and DMARC policies, leading to failed deliveries or inbox placement issues.
Policy drift happens — and it’s silent
When you migrate servers, onboard a new third-party email provider, or add a new sending IP, the existing authentication configuration might no longer reflect reality. SPF records can become outdated, DKIM keys may not be re-signed properly, or DMARC policies might not account for a new relay. Without regular policy reviews, these misalignments go unnoticed, increasing the risk of phishing abuse and domain reputation damage.
Even if your initial setup was flawless, trust erodes over time if you don’t audit your configuration after every technical change. You’re not just protecting your own sends — you’re safeguarding your domain’s reputation across every email gateway, including those used by partners and vendors.
DMARC reports are your early-warning system
DMARC aggregate and forensic reports give you hard data on how your MAIL FROM domain is being used across the internet. They show when unauthorized senders — including compromised or misconfigured third-party relays — attempt to send mail on your behalf. This is especially critical in multi-tenant environments where multiple users or services share infrastructure.
Using tools like inbox placement testing, you can validate whether your authenticated domains are correctly routing to inboxes or getting filtered. Combined with regular DMARC monitoring, this helps detect unauthorized usage before it harms deliverability or triggers blocklists.
If your domain is verified and your sending practices are consistent, you still need to keep your list clean. Invalid or dormant email addresses can degrade sender reputation, especially when they generate bounces or complaints — signals that impact all messages sent under that domain, even if they’re technically authenticated.
That’s where ongoing list hygiene becomes non-negotiable. Using bulk verification tools like EmailListChecker’s allows you to remove invalid, disposable, or high-risk emails before sending, maintaining trust with ISPs and inbox providers. It’s not enough to verify once — you must verify regularly, especially when adding new segments or re-engaging past contacts.
Authentication is a moving target. It’s not just about setting up DKIM and DMARC correctly. It’s about maintaining that setup through change, monitoring real-world signals, and cleaning your data with precision. Your domain’s trustworthiness depends on consistency — not just correctness.
The Bottom Line: Trust in Multi-Tenant Relays Starts with MAIL FROM Control
High deliverability in shared SMTP environments isn’t about avoiding third-party relays. It’s about ensuring that every MAIL FROM domain is independently verified and properly authenticated.
Authentication is non-negotiable
Even when using a multi-tenant relay, trust is only maintained when each sending domain complies with SPF, DKIM, and DMARC policies. Without this, inbox placement drops, and sender reputation suffers.
Control is not ownership
You don’t need to run your own mail server to maintain control. What matters is having systems that enforce authentication at scale and validate email addresses before sending.
Verifying email addresses and enforcing sender policies together form the foundation of reliable, high-trust delivery — regardless of the infrastructure used.
Sources
- DMARC adoption among the world's top 1.8 million domains jumped from 27.2% in 2023 to 47.7% in 2025 — a 75% surge driven by Google and Yahoo's sender rules. — EasyDMARC DMARC Adoption Report 2025 (2025)
- By early 2026, 937,931 of 1.8 million analyzed domains had valid DMARC records — up 79% in three years — but about 56% of them still sit at monitoring-only p=none. — DMARC Report (EasyDMARC 2026 data) (2026)
Keep reading
- Email authentication: SPF, DKIM, DMARC and BIMI (complete guide)
- Resilient Email Delivery with Automatic Re-Connection After TLS Failure
- Email Verification Platform for Slow TLS Negotiation in Mixed Protocol Ecosystems
- Email Verification API with TLS Handshake Failure Support in 2026
- Why SERVFAIL Occurs During SPF Validation and How to Prevent It
Ready to put this into practice? Emaillistchecker.io verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
What is MAIL FROM domain authentication?
It’s the process of verifying that the sending domain in the SMTP envelope is authorized to send mail from a given IP or relay. It prevents spoofing and improves inbox placement.
Why is MAIL FROM authentication critical for multi-tenant SMTP relays?
Without it, one client’s misstep can harm sender reputation across shared domains. Authentication isolates risk and ensures only authorized senders use each domain.
Can SPF or DKIM alone secure MAIL FROM?
No. SPF checks the sending IP; DKIM checks message integrity. Neither validates the MAIL FROM domain directly. DMARC is required to enforce policy based on SPF and DKIM.
How does email verification impact MAIL FROM trust?
It reduces bounce rates and spam complaints by removing invalid, role, and disposable addresses. This keeps sender reputation healthy and enhances the effectiveness of domain authentication.
Does using a shared relay mean I lose control over deliverability?
Not if you enforce domain authentication and validate your list. With proper configuration and verification, you retain control over deliverability, even in shared environments.
What happens if MAIL FROM authentication fails?
The email is likely blocked, marked as spam, or quarantined. Receiving servers use the MAIL FROM domain to assess sender legitimacy — failure undermines trust.
How can I test my MAIL FROM authentication setup?
Use tools like MXToolbox or MxToolbox’s DMARC analysis to check SPF, DKIM, and DMARC records. Test with real messages through a verification service like Emaillistchecker.io.
What is a catch-all email, and why does it harm deliverability?
A catch-all accepts all emails sent to a domain, even invalid addresses. It’s often abused by spammers, leading to high bounce rates and reduced sender reputation.
Can I use a third-party verification service with a multi-tenant SMTP relay?
Yes. Services like Emaillistchecker.io offer bulk and API verification to clean your list before sending — ensuring only valid, responsive addresses are used.
How do role accounts like admin@ or sales@ affect deliverability?
They often go unanswered, leading to high bounce or complaint rates. They’re typically not monitored and can trigger spam filters, hurting sender reputation.
Does Emaillistchecker.io support real-time verification with SendGrid?
Yes. Emaillistchecker.io integrates with SendGrid, Mailchimp, and other platforms, allowing real-time verification to improve list quality and deliverability.
Why does Emaillistchecker.io’s accuracy matter for domain authentication?
High verification accuracy (98.9%) ensures that only valid, deliverable addresses are sent. This reduces bounce risk and maintains sender reputation, reinforcing the effectiveness of MAIL FROM domain authentication.