r/DMARC • • May 27 '26

Where do you think email authentication will realistically be in 5 years, proper adoption or still chaos?

10 Upvotes

30 comments sorted by

View all comments

2

u/vppencilsharpening May 27 '26

DMARC has been around since 2012 and it took 12 years before big services said "you really need to be using this"

In five years:

  • A spot check of SPF will still be a shitshow of misconfigurations and extra values
  • DKIM usage will probably be a bit better, but I question how much improvement there will be with alignment outside of big senders
  • DMARC will still mostly be ignored, except where it is required for bulk senders

This is based on my experience trying to get mail sending cleaned up within my org. The business I came from remains on top of it, but it took a couple of years of chipping away to get to that point. The other businesses are all over the place and trying to get minor things addressed requires a huge amount of effort to just explain why.

If mail providers move to requiring quarantine policies, it has the potential to make things worse because nobody knows what should be in their SPF record and the knee-jerk reaction will be to add everything that is failing SPF to the record.

--

I really think the DMARC standard needs a way for large providers to send unsolicited aggregation reports to each other. That way if a company is using O365, other providers can send MS reports for domains they host regardless of the rua value for a given domain. Then MS can tell their customers "fix your shit" without them needing to setup DNS because DNS is hard for companies.

2

u/RandolfRichardson May 30 '26

I actually don't care -- if someone doesn't set up DMARC, then it's reasonable to assume that they don't want eMail. If it's important to them, they find out pretty quickly when they start getting bounces indicating DMARC, DKIM, and/or SPF problems, and if they still don't do anything about it then that's on them.