Skip to content

standard

DMARC

DMARC (RFC 7489) is an email authentication standard built on SPF and DKIM, letting domain owners set policies for unauthenticated mail and get reports.

Known aliases

  • Domain-based Message Authentication, Reporting and Conformance
  • Domain-based Message Authentication, Reporting, and Conformance
  • p=none
  • p=quarantine
  • p=reject
  • RFC 7489

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

DMARC fails mail that passes SPF and DKIM under the wrong domain

Transactional mail can pass SPF and DKIM and still fail DMARC when neither aligns with the visible From domain, a dev.to Node.js guide shows. Because forwarding breaks SPF, the author treats aligned DKIM as the path to protect.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence50
invest5 publishers

Revolut released passports and Bitcoin histories on an email that passed domain authentication

The request came from an unauthorized account on a real government domain, and Revolut acted on it. The company calls the number of affected customers limited, and it declined to say how many or name the agency.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 55%
Investor
Investor 22%

Reality

Evidence68
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence66
build1 publisher

Two records for one DNS entry turn a verified badge into a drift check

A dev.to onboarding design keeps the SPF, DKIM and DMARC values you generated in one row and the answers a resolver returned in another. Its comparator is a single stripped string match, so an SPF value the customer appended to lands in drifted.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives20
Confidence60

Earlier coverage

  1. Direct Send carried 29,785 spoofed internal emails past the mail gateway in two months

    Security · September 11, 2026 · 1 publisher

  2. A lapsed Carnival promo domain routed authenticated booking mail into a cloaked malware network

    Build · September 10, 2026 · 1 publisher

  3. Trezor's spoofed alert reused the language of the $112.7m Coldcard exploit

    Invest · September 10, 2026 · 1 publisher

  4. Cloudflare's send_email binding reaches only verified addresses until onboarding finishes

    Build · September 7, 2026 · 1 publisher

  5. IPQS scores a ten-year domain 95 with no malicious artifact in its own report

    Build · August 29, 2026 · 1 publisher

  6. SPF and DMARC records that pass every free checker and stop nothing

    Build · August 24, 2026 · 1 publisher

  7. Buy transactional email on recovery controls, not send price

    Build · August 20, 2026 · 1 publisher

  8. 1,400 npm maintainer domains, 18 flags, and one word doing too much work

    Build · August 18, 2026 · 1 publisher

  9. Ransomware's price point is $10m to $1bn in revenue, and it is not moving

    Security · August 18, 2026 · 1 publisher

  10. Judge transactional email on retries and DKIM alignment, not open rates

    Build · August 17, 2026 · 1 publisher

  11. Email and Slack disagree on what a conversation is, and the join key is the envelope

    Build · August 15, 2026 · 1 publisher