Wednesday, 22 January 2025

Collaborative Email Authentication with DMARC

DMARC is an email authentication policy covered by RFC7489.

It stands for "Domain-based Message Authentication, Reporting and Conformance" and builds on SPF and DKIM protocols.  SPF and DKIM were invented for email authentication - the problem of validating whether this email that claims to come Jack really came from Jack. More details on why DKIM was needed and the threats it is intended to protect from are detailed in RFC4686. DKIM stands for DomainKeys Identified Mail.

DMARC improves on DKIM and other protocols in the way described emphasising collaboration between senders and receivers.

Some documents may describe DMARC as a replacement for ADSP. ADSP is an optional extension of DKIM and stands for Author Domain Signing Practices where a domain can publish the signing practices it utilizes when relaying mail on behalf of authors. It did not have much adoption.

No comments: