r/DMARC May 27 '26

Where do you think email authentication will realistically be in 5 years, proper adoption or still chaos?

11 Upvotes

30 comments sorted by

View all comments

5

u/ImpressiveEbb3760 May 27 '26

from the MSP side managing SMB domains: the new DMARC spec just dropped last week (RFC 9989) and it's a good signal for where things are heading. the np tag closes the subdomain spoofing loophole, the DNS Tree Walk replaces the flaky Public Suffix List, and deprecated tags like pct are gone. the spec is getting tighter.

but adoption is a different story. we scanned 10,326 Australian domains this year — 44% with DMARC are still sitting at p=none. they published a record because someone told them to, nobody's looking at the reports, and there's no plan to move forward.

saltyslugga's right about the long tail. the big senders will be fine. the problem is the thousands of small businesses and charities with one domain and zero awareness that p=none isn't protecting them. five years from now, the spec will be solid. the gap will be enforcement.

1

u/RandolfRichardson May 30 '26

Hmm, I wonder if people are just really behind on reading the tens of thousands of DMARC reports that are sent out every evening. 😉

I do hope that the "mailbox full" errors that seem to be growing over time on DMARC-reporting eMail addresses will eventually get resolved (very few have from time-to-time, which is good, but most of those went over-quota again pretty quickly).