![](/static/253f0d9b/assets/icons/icon-96x96.png)
![](https://links.hackliberty.org/pictrs/image/b6380fd7-890f-45ee-a203-5d4745ac857f.webp)
That mismatch between DMARC verification domain and the domain of the “from” header is called DMARC Alignment. Any modern spam filter is going to mark unaligned messages as spam. Especially if one of the domains is completely non-routable like .onion.
And even if you sent the email and it got through with your .onion address, no one would be able to reply to you because the replying mail server can’t even look up the MX record for your .onion domain.
So long as you have robust data sanitization on the backend to prevent XSS and HTML injection attacks…
If you can get away with just using Markdown, you should definitely use that instead of full HTML.