technical · sourced answer
DMARC: Domain-based Message Authentication, Reporting and Conformance
DMARC is an email authentication protocol that uses SPF and DKIM to verify a sender's identity. It allows domain owners to publish a policy in their DNS records specifying how receiving mail servers should handle emails that fail authentication checks.
Mechanical Operation
DMARC functions by checking for alignment between the domain in the From header and the domains validated by SPF and DKIM. If a message passes either SPF or DKIM and the domain matches the From header, it is DMARC compliant. If both fail or lack alignment, the receiver applies the policy defined in the DMARC DNS record: none, quarantine, or reject.
Sender Importance
DMARC prevents unauthorized parties from spoofing a domain to send phishing emails. By moving from a none policy to reject, senders ensure that only authenticated mail reaches the recipient. This reduces the risk of brand impersonation and helps maintain a positive sender reputation across major mail providers.
Operational Considerations
A common mistake is implementing a reject policy before analyzing reporting data. Senders should start with p=none to monitor legitimate third party senders that may be failing authentication. Using SendHQ or its free tools (https://sendhq.cc/tools) can help identify these gaps before enforcing a strict policy that might block valid mail.
Concrete Example
A DMARC record is a TXT record at _dmarc.example.com. An example record v=DMARC1; p=quarantine; rua=mailto:reports@example.com tells the receiver to send failed mail to a quarantine folder and send aggregate XML reports to the specified email address for analysis.
Reporting Mechanisms
DMARC provides two types of reports. Aggregate reports (RUA) provide high level data on which IPs are sending mail on behalf of the domain and their authentication status. Forensic reports (RUF) provide detailed copies of individual messages that failed authentication, allowing for deep technical debugging of delivery issues.
Questions teams ask
Does DMARC replace SPF and DKIM?
No, DMARC builds upon SPF and DKIM. It requires at least one of them to be present and aligned to validate the sender identity.
What is the difference between quarantine and reject?
Quarantine tells the receiver to put failed emails in the spam folder, while reject tells the receiver to block the email entirely.
What is DMARC alignment?
Alignment occurs when the domain in the visible From header matches the domain validated by the SPF record or the DKIM signature.
Primary sources
- RFC 7489: Domain-based Message Authentication, Reporting and Conformance — RFC Editor
- RFC 7208: Sender Policy Framework — RFC Editor
- RFC 6376: DomainKeys Identified Mail — RFC Editor