Tag
The article details the author's experiences with email forwarding challenges due to authentication protocols like SPF, DKIM, and DMARC, and describes various attempts to resolve the issue using tools such as Outlook rules and Cloudflare services.
Ten years of DNS measurements show email infrastructure consolidating around two providers, DMARC enforcement plateauing, and a large long tail of infrastructure, raising resilience concerns.
Explains what DMARC actually protects against, clarifying its narrow scope relative to SPF and DKIM, and why it is not a spam or phishing filter.
A CipherCue analysis of 67,336 domains finds that 68.4% still do not enforce DMARC, despite the standard being public since 2012, with many domains stuck in monitoring mode due to the difficulty of authenticating all legitimate email sources.
The article details a newly discovered incompatibility between DMARC's 'np' tag (RFC 9989) and DNSSEC's Compact Denial of Existence (RFC 9824), causing the tag to malfunction for domains using DNSSEC with major DNS providers. The IETF acknowledged the issue but has not yet reached a solution.
This IETF draft recommends reclassifying the ARC (Authenticated Received Chain) protocol as historic, concluding its experiment and pointing to DKIM2 as a successor.
Fastmail examines how AI-driven email filtering and assistants are making email authentication standards (SPF, DKIM, DMARC) critical infrastructure to prevent spoofing and phishing.