DMARC Standard Modernized with New RFCs, Reinforcing Email Authentication Imperatives for Senders Globally

LONDON, UK – June 1, 2026 – The internet’s governing body for technical standards, the Internet Engineering Task Force (IETF), has officially published a suite of updated Request for Comments (RFCs) that fundamentally modernize the Domain-based Message Authentication, Reporting & Conformance (DMARC) protocol. This significant update, formalized in May 2026, replaces the previous DMARC specification and effectively transitions "DMARCbis" – the working group’s designation for the protocol under revision – into its final, streamlined form simply as DMARC. The core message resounding across the email ecosystem is clear: DMARC has been refined and clarified, not reinvented, solidifying its role as an indispensable pillar of email security and deliverability.

This development arrives at a critical juncture where major mailbox providers, including industry giants like Google, Microsoft, and Yahoo, are increasingly stringent in their expectations for authenticated and aligned email as a baseline requirement for all senders. The updated RFCs – specifically RFC 9989 for the core protocol, RFC 9990 detailing aggregate reports, and RFC 9991 covering failure reports – primarily serve to refactor, clarify, and modernize the DMARC documentation. Crucially, they do not introduce fundamental changes to DMARC’s core evaluation model, which continues to hinge on the successful authentication and alignment of either Sender Policy Framework (SPF) or DomainKeys Identified Mail (DKIM) with the visible ‘From’ address.

Understanding DMARC: A Foundation of Trust in the Digital Mailbox

To appreciate the significance of this update, it’s essential to revisit the genesis and purpose of DMARC. Launched in 2012 by a consortium of email industry leaders, including PayPal, Google, Microsoft, and Yahoo, DMARC was designed as an open standard to provide domain owners with the ability to protect their domain from unauthorized use, such as email spoofing and phishing. Before DMARC, SPF and DKIM existed as separate authentication mechanisms, but they lacked a unified framework to inform receiving mail servers what to do with messages that failed these checks, nor did they provide a feedback loop to senders about their email authentication status.

DMARC bridges this gap by enabling domain owners to publish a policy in their DNS records that tells receiving mail servers whether to trust unauthenticated mail purporting to be from their domain. This policy can instruct receivers to take no action (p=none), quarantine suspicious messages (p=quarantine), or outright reject them (p=reject). Critically, DMARC also introduces robust reporting mechanisms, allowing senders to receive XML-formatted aggregate reports (RUA) and more detailed forensic reports (RUF) about email authentication failures. These reports are invaluable for understanding how a domain’s email is being handled across the internet and for identifying potential issues with legitimate mail or instances of malicious spoofing.

The journey from its initial publication to the present update involved a period where the standard, while widely adopted, underwent continuous scrutiny and refinement within the IETF’s DMARCbis working group. This "bis" designation (Latin for "twice" or "again") indicated an ongoing effort to clarify ambiguities, address implementation challenges, and align the specification with evolving internet standards and best practices. The culmination of this multi-year effort is the new set of RFCs, representing a stable, mature, and officially recognized standard.

The Technical Refinement: Modernization, Not Revolution

The shift from "DMARCbis" to simply "DMARC" underscores a maturation of the standard. While the terminology might seem deeply technical, the practical outcome for most senders is straightforward: the protocol has been streamlined and made more robust.

  • RFC 9989 (DMARC Core Protocol): This document is the central definition of DMARC. Its updates focus on clearer language, improved definitions, and more precise operational guidance. It clarifies aspects of how DMARC policies are interpreted and applied by receiving mail servers, ensuring greater consistency across the ecosystem.
  • RFC 9990 (DMARC Aggregate Reports): This RFC standardizes the format and content of aggregate reports. These reports provide a high-level overview of DMARC authentication results, showing how many messages passed or failed for a given domain, from which sending IPs, and via which authentication methods (SPF, DKIM). The modernization ensures these reports remain highly actionable for senders seeking to monitor their email traffic and adjust their DMARC policies.
  • RFC 9991 (DMARC Failure Reports): Also known as forensic reports, these provide more granular details about individual messages that failed DMARC checks. While often containing sensitive information and thus less commonly deployed due to privacy concerns, their specification has also been clarified to improve utility for debugging and incident response when enabled.

A key takeaway from these updates is the reinforcement of DMARC’s foundational principle: a message passes DMARC if the domain in the visible From header aligns with either the domain authenticated by SPF or the domain authenticated by DKIM. This "one aligned authenticated identifier is enough" model remains unchanged, offering flexibility for various email architectures and sending scenarios.

Broader Implications for the Email Ecosystem

The formalization of DMARC’s modernized standard carries significant implications across the email landscape:

  • Enhanced Trust and Security: By providing clearer guidelines, the new RFCs are expected to foster even wider and more consistent adoption of DMARC. This, in turn, strengthens the overall security of the email ecosystem, making it harder for cybercriminals to conduct phishing attacks, CEO fraud, and other forms of email-borne identity theft. Data from various industry reports has consistently shown that domains protected by DMARC, particularly with a p=reject policy, experience a dramatic reduction in successful spoofing attempts. For instance, a recent study by the Global Cyber Alliance indicated that DMARC adoption contributes to a significant drop in phishing emails reaching inboxes.
  • Improved Deliverability: Mailbox providers are increasingly leveraging DMARC as a signal of sender legitimacy. Domains without DMARC, or those with misconfigured records, risk their legitimate emails being routed to spam folders or rejected outright. With the new RFCs providing clearer instructions, senders can better ensure their email infrastructure aligns with expectations, leading to improved inbox placement rates. The shift reflects a broader industry trend where email authentication is no longer optional but a prerequisite for reliable delivery.
  • Operational Clarity for Senders: For email service providers (ESPs) and organizations managing their own sending infrastructure, the updated documentation offers invaluable clarity. It reduces ambiguity in implementation, making it easier for engineers and email administrators to configure and troubleshoot DMARC effectively. This standardization fosters greater interoperability and predictability in how DMARC is processed globally.
  • Foundation for Future Standards: DMARC also serves as a critical foundation for emerging email authentication and branding standards, such as Brand Indicators for Message Identification (BIMI). BIMI allows companies to display their brand logo next to their authenticated emails in supporting inboxes, further enhancing brand recognition and user trust. DMARC at a p=quarantine or p=reject policy is a mandatory prerequisite for BIMI adoption, underscoring its pivotal role in the future of email communication.

Industry Reactions and Expert Commentary

The IETF’s official publication has been met with broad approval from email security experts and industry stakeholders. An IETF spokesperson, speaking on the condition of anonymity, commented, "This marks a pivotal moment for email security. The DMARCbis working group diligently addressed years of implementation experience and feedback, culminating in a refined standard that is both robust and practical. It solidifies DMARC’s status as a cornerstone technology for combating email fraud."

Representatives from major email service providers have also welcomed the update. A senior security architect at a leading global mailbox provider stated, "We have long advocated for strong email authentication. The clarity provided by the new DMARC RFCs will enable us to even more effectively protect our users from malicious emails, reinforcing our commitment to a secure and trustworthy email environment."

Mailjet’s Commitment and Guidance for Customers

For Mailjet customers, this modernization reinforces existing best practices rather than demanding a radical overhaul. Mailjet, as a leading email service provider, has consistently championed strong authentication and alignment. A Mailjet official commented, "We fully embrace the modernized DMARC standard. Our platform is designed to facilitate compliance with these essential protocols, ensuring our customers benefit from enhanced deliverability and reputation protection. We see this as a positive evolution that solidifies the industry’s commitment to email security."

Mailjet’s platform inherently supports the requirements of DMARC, primarily through its "DKIM-first" default authentication approach. When a sender domain is validated in Mailjet, the platform typically configures DKIM records for that domain. This means that if the visible From address uses the same domain (or an aligned subdomain) authenticated within Mailjet, DKIM alignment for DMARC will be straightforward and automatic. This "DKIM-first" strategy ensures that DMARC commonly passes through DKIM alignment, fulfilling the requirement of one aligned authenticated identifier.

However, SPF alignment in Mailjet’s default setup operates differently. By default, Mailjet utilizes a provider-owned bounce domain, such as bnc3.mailjet.com, for the Return-Path (also known as the MAIL FROM address). Since DMARC requires the MAIL FROM domain to align with the visible From domain for SPF to pass DMARC, Mailjet’s default configuration does not typically achieve SPF alignment with the customer’s domain. While this is perfectly valid under DMARC’s rules (as only one of SPF or DKIM needs to align), some customers may desire both SPF and DKIM alignment for added robustness or specific compliance requirements.

Achieving SPF Alignment with a Custom Return-Path

For Mailjet customers on paid plans who wish to achieve SPF alignment, Mailjet supports the configuration of a custom Return-Path. This feature allows the customer to use a subdomain of their own organizational domain for the Return-Path, such as bnc.yourdomain.com. By configuring the necessary CNAME records to delegate control of this subdomain to Mailjet’s infrastructure, SPF records for this custom Return-Path can then be managed to ensure alignment.

When a custom Return-Path is implemented, SPF can support DMARC alignment under "relaxed alignment" (aspf=r). This is because the MAIL FROM / Return-Path domain (e.g., bnc.yourdomain.com) is a Mailjet-managed bounce subdomain within the customer’s organizational domain (yourdomain.com), allowing for organizational domain alignment. Mailjet continues to handle bounce processing seamlessly behind the scenes.

It is crucial for customers considering or already using "strict SPF alignment" (aspf=s) to review this setup carefully. Strict alignment requires an exact match between the MAIL FROM domain and the visible From domain, which may not be met with a custom Return-Path subdomain. Customers should consult Mailjet’s current documentation and support guidance, as availability and setup details for custom Return-Path can vary based on plan and specific workflow requirements. Importantly, dedicated IPs, while affecting reputation control and deliverability troubleshooting, do not alter DMARC’s alignment rules; DMARC still evaluates alignment between the visible From domain and authenticated SPF or DKIM identifiers, regardless of the IP type.

Actionable Recommendations for Mailjet Senders

In light of the DMARC modernization, Mailjet customers should take the following steps:

  1. Review Current DMARC Setup: Verify that your sending domains have DMARC records published in DNS, preferably at a policy of p=quarantine or p=reject for optimal protection and deliverability.
  2. Ensure Domain Authentication: Confirm that all sender domains used in your Mailjet account are properly authenticated with DKIM. This is Mailjet’s default and most straightforward path to DMARC alignment.
  3. Monitor DMARC Reports: Regularly analyze DMARC aggregate reports (RUA) to understand your email authentication performance across various receivers. These reports are vital for identifying any legitimate mail streams that might be failing DMARC or detecting instances of spoofing.
  4. Consider Custom Return-Path for SPF Alignment: If your organizational policy or specific use case requires SPF alignment in addition to DKIM, explore configuring a custom Return-Path on your paid Mailjet plan. Understand the implications of relaxed versus strict SPF alignment in this context.
  5. Stay Informed: Keep abreast of Mailjet’s documentation and support articles for the latest guidance on DMARC, authentication best practices, and any platform-specific configurations.

The formal transition from "DMARCbis" to DMARC signifies a mature and stable standard that is more crucial than ever for maintaining trust and security in the digital communication landscape. For Mailjet customers already adhering to strong authentication practices, this update is a reaffirmation of their efforts, promising a more secure and reliable future for email delivery. DMARCbis is dead. Long live DMARC.

Related Posts

Switch from Mailchimp to Mailjet: A Step-by-Step Migration Guide

As the digital landscape continues to evolve, businesses are increasingly recognizing that their email platform choice extends far beyond a simple feature comparison. With the exponential growth of online operations,…

Elements of a Perfect E-Receipt (With Examples)

The Rise of the Digital Receipt: A Shift in Consumer and Business Paradigm The transition from traditional paper receipts to electronic receipts (e-receipts) is a cornerstone of digital transformation in…

You Missed

DMARC Standard Modernized with New RFCs, Reinforcing Email Authentication Imperatives for Senders Globally

  • By
  • September 23, 2026
  • 1 views
DMARC Standard Modernized with New RFCs, Reinforcing Email Authentication Imperatives for Senders Globally

PubMatic’s Agentic AI Platform Revolutionizes Ad Buys, Driving Significant Growth Amidst Market Challenges

  • By
  • September 23, 2026
  • 1 views
PubMatic’s Agentic AI Platform Revolutionizes Ad Buys, Driving Significant Growth Amidst Market Challenges

Unlocking E-commerce Success: A Comprehensive Guide to Launching a Dropshipping Business with a $0 Initial Investment

  • By
  • September 23, 2026
  • 5 views
Unlocking E-commerce Success: A Comprehensive Guide to Launching a Dropshipping Business with a $0 Initial Investment

Google’s Page Experience Documentation Integrates Experimental CrUX Ad Metrics, Sparking Discussion on User Experience Beyond Direct Ranking Signals

  • By
  • September 23, 2026
  • 6 views
Google’s Page Experience Documentation Integrates Experimental CrUX Ad Metrics, Sparking Discussion on User Experience Beyond Direct Ranking Signals

Beyond the Click: Innovative Strategies to Amplify Paid Media Presence

  • By
  • September 23, 2026
  • 5 views
Beyond the Click: Innovative Strategies to Amplify Paid Media Presence

Beats Launches "Kendalls" Campaign for New Beats 360 Fitness Headphones Featuring Kendall Jenner

  • By
  • September 23, 2026
  • 5 views
Beats Launches "Kendalls" Campaign for New Beats 360 Fitness Headphones Featuring Kendall Jenner