Domain-based Message Authentication, Reporting, and Conformance
RFC 7489, “Domain-based Message Authentication, Reporting, and Conformance”, is an Informational document published in March 2015 by M. Kucherawy, E. Zwicky. It has since been updated by RFC 8553, RFC 8616. It has been obsoleted by RFC 9989, RFC 9990, RFC 9991 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
Domain-based Message Authentication, Reporting, and Conformance (DMARC) is a scalable mechanism by which a mail-originating organization can express domain-level policies and preferences for message validation, disposition, and reporting, that a mail-receiving organization can use to improve mail handling.
Originators of Internet Mail need to be able to associate reliable and authenticated domain identifiers with messages, communicate policies about messages that use those identifiers, and report about mail using those identifiers. These abilities have several benefits: Receivers can provide feedback to Domain Owners about the use of their domains; this feedback can provide valuable insight about the management of internal operations and the presence of external domain name abuse.
DMARC does not produce or encourage elevated delivery privilege of authenticated email. DMARC is a mechanism for policy distribution that enables increasingly strict handling of messages that fail authentication checks, ranging from no action, through altered delivery, up to message rejection.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 7489 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7488 Port Control Protocol Server Selection
- RFC 7490 Remote Loop-Free Alternate Fast Reroute
- RFC 7487 Configuration of Proactive Operations, Administration, and Maintenance Functions for MPLS-Based Transport Networks Using RSVP-TE
- RFC 7491 A PCE-Based Architecture for Application-Based Network Operations
- RFC 7486 HTTP Origin-Bound Authentication
- RFC 7492 Analysis of Bidirectional Forwarding Detection Security According to the Keying and Authentication for Routing Protocols Design Guidelines
- RFC 7485 Inventory and Analysis of WHOIS Registration Objects
- RFC 7493 The I-JSON Message Format