Tag
Explains what DMARC actually protects against, clarifying its narrow scope relative to SPF and DKIM, and why it is not a spam or phishing filter.
A CipherCue analysis of 67,336 domains finds that 68.4% still do not enforce DMARC, despite the standard being public since 2012, with many domains stuck in monitoring mode due to the difficulty of authenticating all legitimate email sources.
The article details a newly discovered incompatibility between DMARC's 'np' tag (RFC 9989) and DNSSEC's Compact Denial of Existence (RFC 9824), causing the tag to malfunction for domains using DNSSEC with major DNS providers. The IETF acknowledged the issue but has not yet reached a solution.
This IETF draft recommends reclassifying the ARC (Authenticated Received Chain) protocol as historic, concluding its experiment and pointing to DKIM2 as a successor.
Fastmail examines how AI-driven email filtering and assistants are making email authentication standards (SPF, DKIM, DMARC) critical infrastructure to prevent spoofing and phishing.