Skip to content

DMARC Introduces New Email Authentication Rules for Domain Protection

DMARC Introduces New Email Authentication Rules for Domain Protection

The Internet Engineering Task Force (IETF) has updated DMARC standards. The new standards introduce several changes that improve reporting, clarify how domains are identified, and strengthen privacy protections.

What is New:

  • np= tag: Lets you set a policy for emails claiming to come from non-existent subdomains. You can tell mail providers to reject spoofed messages sent from fake subdomains that don’t exist.
  • DNS Tree Walk replaces the Public Suffix List: DMARC now identifies an organizational domain using a DNS Tree Walk instead of relying on the Public Suffix List. This makes domain discovery part of the standard itself.
  • psd= tag becomes part of the core standard: Support for Public Suffix Domains (PSDs), previously defined in RFC 9091, is now built directly into DMARC. You can declare whether a domain is a Public Suffix Domain.

What has Changed

  • SPF alignment now checks only the MAIL FROM address: DMARC no longer falls back to the HELO/EHLO identity during SPF evaluation. If your setup relied on that fallback, you may need to review your email configuration.
  • Failure reporting adds stronger privacy guidance: The updated standard encourages limiting sensitive information in failure reports because they can contain personal or confidential email data.

What has been deprecated

  • pct= deprecated: The percentage rollout option is no longer recommended. The updated standard moves away from gradual percentage-based policy deployment.
  • rf= deprecated: The report format tag is no longer recommended for new deployments.
  • ri= deprecated: The reporting interval tag has been deprecated.
  • Report size limits removed from rua=: Aggregate report URIs no longer support report size limit notation

These updates make DMARC more predictable and easier to implement across different email providers.

The additional np= option lets you extend protection to subdomains that do not exist but could still be abused by attackers.

The revised standards also place much greater emphasis on privacy by encouraging limiting sensitive information, validating report destinations, and using secure transport to reduce privacy risks for Failure reports.

If your deployment still depends on deprecated tags, you should plan to remove them over time. If your email workflow relied on SPF falling back to the HELO identifier, that behavior no longer applies under the updated standard.

Info: The update comes through three new standards, RFC 9989, RFC 9990, and RFC 9991, which replace the previous DMARC specifications and move the protocol onto the IETF Standards Track.

Categories: Category: Email Marketing News
Elvis M.

I have over 10 years of experience developing email marketing tools, having worked on a number of projects, including helping a bank with over 20 million customers run its email marketing. I also created an email-related WordPress plugin with over 30,000 installs and a self-hosted email marketing platform that was acquired. Most recently, I developed this Contact Exporter Google Workspace App. I am also a media and communication graduate and a certified journalist.

Email Elvis M.

Latest Posts