RFC 9989: DMARC: Domain-based email authentication
Summary
RFC 9989 updates DMARC for policies, alignment and reports based on SPF and DKIM. Email authentication is an interplay of several DNS and signature mechanisms. Strict policies first need reliable observation.
Ideas
- Alignment compares the visible sender domain with authenticated domains.
- Policies describe how failures should be handled.
- Reports make abuse and misconfiguration visible.
Facts
- RFC 9989 replaces RFC 7489.
Remarks
- RFC 9989 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Start with reports and tighten policies in a controlled way.
- Monitor legitimate sending services, forwarding and mailing lists.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.