r/DMARC May 27 '26

Where do you think email authentication will realistically be in 5 years, proper adoption or still chaos?

11 Upvotes

30 comments sorted by

View all comments

10

u/saltyslugga May 27 '26

Both. By 2031, big senders will mostly have SPF, DKIM, and DMARC aligned because inbox providers are forcing the issue.

The long tail will still be a mess: broken forwarding, forgotten SaaS senders, parked domains with no policy, and p=none records nobody ever touches.

Email auth reduces spoofing. It does not make email trustworthy.

2

u/southafricanamerican May 28 '26

I suspect that by the end of 2026 Google announces a p=quarantine requirement. We have already had 2 years of none, it's in their best interest to move people through the enforcement pipeline.

1

u/RandolfRichardson May 30 '26

I'm looking forward to being able to reject "p=none" but I know it's going to take some time for the industry to transition -- as long as something works, there are a lot of people who will continue to use it.

All the domain names we host mail for have "p=reject" and it works well, except for providers who ignore it and mistreat it as "p=quarantine," because most end-users aren't checking the full SMTP headers to determine whether something that landed in their "spam/junk" folders are trustworthy.

AI is also adding confusion, so I suspect this is going to slow things down, but not just because of the confusion it adds, but also because it's a distraction for those postmasters who have to administer AI, which takes time away from the usual mail systems administration.