The New DMARC Era: IETF Modernizes Email Authentication Standard, Reaffirming Best Practices for Senders

June 1, 2026, marks a significant moment in the ongoing evolution of email security and deliverability standards as the Internet Engineering Task Force (IETF) officially replaced the foundational DMARC (Domain-based Message Authentication, Reporting, and Conformance) specification with a set of modernized RFCs. This update, culminating in the publication of RFC 9989 (core protocol), RFC 9990 (aggregate reports), and RFC 9991 (failure reports) in May 2026, consolidates and clarifies the protocol previously known colloquially as DMARCbis. For email service providers like Mailjet and their extensive customer base, the practical takeaway is one of refinement rather than revolution: DMARC has been modernized, not reinvented, emphasizing the critical importance of robust email authentication and diligent monitoring.

Understanding DMARC: A Foundation for Trust in Email Communication

At its core, DMARC is an email authentication protocol designed to protect organizations from email spoofing, phishing, and other forms of cyber fraud. It builds upon two existing authentication methods: SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail). SPF allows domain owners to specify which mail servers are authorized to send email on their behalf, while DKIM provides a cryptographic signature that verifies the sender’s identity and ensures the message hasn’t been tampered with in transit. DMARC acts as the policy layer, instructing recipient mail servers on how to handle emails that fail SPF or DKIM checks, and providing a mechanism for senders to receive reports on their email authentication performance.

The genesis of DMARC stemmed from a growing need to combat the pervasive problem of email abuse. Prior to its widespread adoption, malicious actors could easily impersonate legitimate senders, leading to significant financial losses, reputational damage, and a erosion of trust in email as a communication medium. DMARC emerged from a collaborative effort involving major email providers and senders, recognizing that a unified approach to authentication was essential. Its primary function is to check whether the domain in the visible From address (the one users see) aligns with the authenticated domains verified by SPF or DKIM. Crucially, DMARC requires only one of these identifiers to be aligned and authenticated for an email to pass inspection, offering flexibility in implementation.

A Chronology of Evolution: From RFC 7489 to the DMARC Renaissance

The journey to the current DMARC specification began over a decade ago. The original DMARC protocol was first formally defined in RFC 7489, published in March 2015. This groundbreaking document established the framework for domain owners to assert their email authentication practices and receive feedback. However, as the internet and email ecosystem continued to evolve, so did the need for clearer definitions, improved reporting mechanisms, and general modernization.

The term "DMARCbis" emerged informally within the IETF’s DMARC working group, signaling an ongoing effort to revise and refine the original specification. This "bis" (Latin for "twice") phase involved extensive discussions, proposals, and reviews from a broad community of experts, including email service providers, mailbox providers, cybersecurity researchers, and enterprise senders. The goal was not to fundamentally alter DMARC’s core logic but to enhance its robustness, address ambiguities, and integrate lessons learned from years of real-world deployment. This iterative process, characteristic of IETF standards development, ensures that internet protocols remain relevant and effective in the face of evolving threats and technological advancements.

The culmination of this multi-year effort arrived in May 2026 with the official publication of the three new RFCs:

  • RFC 9989: DMARC: Domain-based Message Authentication, Reporting, and Conformance – This document supersedes RFC 7489 and defines the core DMARC protocol, outlining how senders declare their authentication policies and how receivers process them. It incorporates clarifications on domain alignment, policy enforcement, and overall protocol behavior.
  • RFC 9990: DMARC Aggregate Report Format – This RFC details the standardized XML format for DMARC aggregate reports, which provide senders with high-level summaries of their email traffic, including authentication results, sending sources, and DMARC policy application by recipient mail servers. These reports are invaluable for monitoring email deliverability and identifying potential spoofing attempts.
  • RFC 9991: DMARC Failure Report Format – This document specifies the format for DMARC failure reports (sometimes called forensic reports), which offer more granular, anonymized details about individual messages that failed DMARC authentication. While less commonly used due to privacy concerns and potential data volume, these reports can be crucial for deep-dive investigations into specific authentication failures.

The publication of these RFCs in May 2026 and subsequent announcements, such as Mailjet’s on June 1, 2026, officially usher in the modernized DMARC standard, reinforcing its status as a cornerstone of email security infrastructure.

The Technical Refinements: What’s New in RFC 9989, 9990, 9991

While the new RFCs are substantial in their breadth, they primarily focus on refining and clarifying existing concepts rather than introducing radical changes to DMARC’s operational model. The core principle of "aligned SPF or aligned DKIM" as the basis for DMARC passing remains unchanged. The refactoring efforts aimed to:

  • Improve Clarity and Readability: The original RFC 7489, while foundational, had areas that benefited from clearer language and better structural organization. The new RFCs strive for greater precision in defining terms and processes.
  • Modernize Terminology: Updating language to reflect current industry practices and technological understanding.
  • Address Implementation Nuances: Incorporating best practices and resolving ambiguities that arose during widespread DMARC deployment over the past decade. For instance, clearer guidance on the handling of subdomains and organizational domains in alignment checks.
  • Standardize Reporting: RFC 9990 and 9991 provide more robust and consistent specifications for DMARC reporting, which is crucial for tools and services that parse and present this data to senders. This standardization helps ensure interoperability and consistent interpretation of reports across different providers.

These updates mean that the fundamental mechanism by which DMARC evaluates email—checking if the domain in the visible From header aligns with either the domain authenticated by DKIM or the domain in the SPF-verified Return-Path—continues without alteration. The objective remains to empower domain owners to declare their legitimate sending sources and monitor unauthorized usage, thereby enhancing email trust and security across the internet.

Implications for Email Service Providers and Senders

The modernized DMARC standard has widespread implications, particularly for email service providers (ESPs) and their customers who rely on email for critical communications. With major mailbox providers like Google and Yahoo increasingly enforcing stricter authentication requirements, DMARC compliance is no longer optional but a fundamental prerequisite for optimal deliverability. Industry data consistently shows that domains with DMARC policies set to quarantine or reject experience significantly lower rates of successful phishing attacks and improved inbox placement compared to those without DMARC or with a p=none policy. A recent industry report indicated that DMARC adoption by Fortune 500 companies surpassed 80% in 2023, with government agencies also demonstrating high rates of implementation, underscoring its critical role in enterprise cybersecurity.

Mailjet’s Stance and Default Configurations

For Mailjet customers, the DMARC update reinforces the importance of practices already central to Mailjet’s deliverability philosophy. Mailjet, as a leading ESP, has long emphasized the necessity of domain authentication for its users. The company’s default configurations are designed to facilitate DMARC compliance, primarily through a "DKIM-first" approach.

When a user validates a sender domain in Mailjet, the platform automatically generates and provides CNAME records for DKIM authentication. This process ensures that outbound emails sent through Mailjet are cryptographically signed with a DKIM signature associated with the customer’s domain. Consequently, DKIM alignment is straightforward: if the visible From address uses the same domain (or an aligned subdomain) that has been authenticated in Mailjet, DKIM alignment for DMARC purposes is achieved.

The SPF story with Mailjet’s default setup is slightly different. By default, Mailjet utilizes a provider-owned bounce domain, such as bnc3.mailjet.com, for the Return-Path (also known as the MAIL FROM address). While Mailjet ensures that its sending IPs are authorized via SPF records for this bounce domain, this default configuration typically does not result in SPF alignment for the customer’s From domain. Since the bnc3.mailjet.com domain does not align with the customer’s visible From domain, SPF fails to align with the DMARC policy under strict alignment rules.

However, as DMARC only requires one aligned authenticated identifier (either SPF or DKIM), Mailjet’s default setup commonly passes DMARC through DKIM alignment. This is a perfectly valid and widely accepted method for achieving DMARC compliance. According to Mailjet’s internal documentation and guidance, this DKIM-centric approach ensures robust authentication for the vast majority of its users.

Navigating SPF Alignment with Custom Return-Paths

For Mailjet customers who desire both SPF and DKIM alignment for their DMARC policy, perhaps for enhanced redundancy or specific compliance requirements, Mailjet offers the option of configuring a custom Return-Path. This feature is typically available on paid plans and involves a specific setup process.

With a custom Return-Path, Mailjet allows customers to use a subdomain within their organizational domain (e.g., bounces.yourdomain.com) as the MAIL FROM address. This requires configuring a CNAME record that points to Mailjet’s bounce management infrastructure. Once configured, SPF can support DMARC alignment under relaxed alignment (aspf=r). Relaxed alignment permits the organizational domain of the MAIL FROM address to match the organizational domain of the From header, even if the subdomains differ. Mailjet continues to handle the underlying bounce processing, ensuring efficient feedback loops for deliverability management.

It is critical for customers considering or using strict SPF alignment (aspf=s) to review this setup carefully. Strict alignment demands an exact match between the MAIL FROM domain and the visible From domain. Given Mailjet’s managed bounce subdomain structure for custom Return-Paths, achieving strict SPF alignment with the From header might require advanced configurations or may not be feasible within standard ESP setups. Mailjet advises checking its current documentation and support channels for the latest information on custom Return-Path capabilities, as availability and setup details can evolve. It’s also important to note that typically only one active custom Return-Path can be configured per API key.

Dedicated IPs, while valuable for reputation control and deliverability troubleshooting, do not alter DMARC’s fundamental alignment rules. Whether using shared or dedicated Mailjet IPs, DMARC consistently evaluates the alignment between the visible From domain and the authenticated SPF or DKIM identifiers.

Broader Industry Impact and Expert Perspectives

The modernization of DMARC by the IETF is widely viewed by industry observers and cybersecurity experts as a positive step towards a more secure and trustworthy email ecosystem. "The refinements in the new DMARC RFCs provide much-needed clarity for implementers, ensuring greater consistency and robustness in email authentication," stated a leading cybersecurity analyst. "This isn’t about rewriting the rulebook, but rather polishing it to better withstand the evolving tactics of cybercriminals."

The ongoing pressure from major mailbox providers to adopt and enforce DMARC further underscores its importance. Requirements from giants like Google and Yahoo, mandating DMARC implementation alongside SPF and DKIM for bulk senders, highlight a collective industry movement towards a baseline of authenticated email. This trend ensures that email deliverability is increasingly tied to a sender’s commitment to security standards.

DMARC’s reporting capabilities, particularly the aggregate reports, remain a crucial component. These reports offer senders invaluable insights into their email traffic, allowing them to identify legitimate sending sources, detect unauthorized use of their domain, and fine-tune their DMARC policies. This data-driven approach to email security empowers organizations to proactively manage their sending reputation and protect their brand.

Actionable Steps for Mailjet Senders

In light of the DMARC modernization, Mailjet advises its senders to undertake a comprehensive review of their email authentication practices. While the core requirements remain consistent, ensuring full adherence to best practices is paramount for maintaining optimal deliverability and security.

  1. Review Current Authentication Status: Senders should regularly check their domain’s DMARC, SPF, and DKIM records using online tools. Verify that all legitimate sending sources are authorized and that the DMARC policy is correctly configured (e.g., p=none for monitoring, p=quarantine for isolation, p=reject for full enforcement).
  2. Ensure DKIM is Correctly Set Up and Aligned: For most Mailjet users, DKIM alignment is the primary method for DMARC compliance. Verify that DKIM records are properly configured for all sender domains within Mailjet and that the From domains used in emails align with these authenticated domains.
  3. Consider a Custom Return-Path for SPF Alignment (If Desired): If achieving SPF alignment is a specific requirement or preference, explore Mailjet’s custom Return-Path feature for paid plans. Understand the setup process, the implications for relaxed versus strict SPF alignment, and consult Mailjet’s latest documentation or support for guidance.
  4. Understand DMARC Reporting: Familiarize yourself with the insights provided by DMARC aggregate reports. These reports are essential for monitoring email authentication performance, identifying potential issues, and detecting unauthorized email activity purporting to come from your domain.
  5. Actively Monitor DMARC Aggregate Reports: Implement a process for regularly analyzing DMARC aggregate reports. This ongoing vigilance allows senders to detect and respond to spoofing attempts promptly, troubleshoot any authentication failures, and gradually move towards stronger DMARC policies (p=quarantine or p=reject) with confidence.

In conclusion, "DMARCbis is dead. Long live DMARC." This sentiment perfectly encapsulates the current landscape. For most Mailjet customers already committed to using authenticated domains and correctly aligned identifiers, the new IETF RFCs serve primarily as a clarification of existing best practices rather than a seismic operational shift. The message is clear: robust email authentication, leveraging DMARC in conjunction with SPF and DKIM, is no longer merely a recommendation but an indispensable requirement for any organization seeking to maintain trust, ensure deliverability, and protect its brand in the digital age.

Related Posts

The Indispensable Role of SPF Records in Combating Sophisticated Phishing Attacks and Securing Digital Communications

The digital landscape is increasingly fraught with peril, as cybercriminals continuously refine their tactics, making robust email security measures not merely advisable, but absolutely critical. It might shock you to…

Businesses Increasingly Migrate from Mailchimp to Sinch Mailjet Amid Evolving Digital Marketing Landscape

The digital marketing ecosystem is witnessing a significant trend as businesses increasingly evaluate and transition their email marketing operations from established platforms like Mailchimp to more specialized and scalable solutions…

You Missed

The New DMARC Era: IETF Modernizes Email Authentication Standard, Reaffirming Best Practices for Senders

  • By
  • July 27, 2026
  • 1 views
The New DMARC Era: IETF Modernizes Email Authentication Standard, Reaffirming Best Practices for Senders

The Dilution of Digital Authority: How AI Repurposing Is Quietly Erasing Brand Differentiation and What to Do About It

  • By
  • July 27, 2026
  • 1 views
The Dilution of Digital Authority: How AI Repurposing Is Quietly Erasing Brand Differentiation and What to Do About It

Advanced Google Ads Workshop Updates for 2020 & 2021 and other updates

  • By
  • July 27, 2026
  • 2 views

Fourthwall is the Best Premium Custom Clothing and Apparel Platform

  • By
  • July 27, 2026
  • 2 views
Fourthwall is the Best Premium Custom Clothing and Apparel Platform

Google Comparison Listing Ads Now CSS Product Listing Ads

  • By
  • July 27, 2026
  • 2 views
Google Comparison Listing Ads Now CSS Product Listing Ads

Navigating the 2026 Holiday Marketing Landscape: Strategic LinkedIn Engagement for Measurable Business Outcomes

  • By
  • July 27, 2026
  • 2 views
Navigating the 2026 Holiday Marketing Landscape: Strategic LinkedIn Engagement for Measurable Business Outcomes