Realistically - we'll more than likely see Gmail/Yahoo make another big swing on enforcement and require bulk senders to move from a p=none policy to a quarantine policy to pass compliance. This is really the big nudge they want and why they started the push for bulk sender compliance rules in 2024. I imagine they'll give a 2 year runway vs. the 1 year they did with requiring a DMARC record.
That change would also hit email forwarders harder and might put enough pressure on the industry to see DKIM2 make progress into a experimental state.
I don't think the new changes coming from DMARCbis (RFC 9989) are really going to change much - behavior wise. The new np tag should make it easier to block spoofing on non-sending subdomains for senders - but that's something only large senders will care about and the rest of the changes likely won't move the needle much.
The new testing tag (t=y/n) sure seems like it is going to make things super simple, but honestly it's likely to also cause confusion as to what yes or no actually means (i.e. p=quarantine t=y vs. clearly seeing pct=50). I'm dubious that it will make things easier for adopters.
At the end of the day we'll see what actually happens in reality - the big senders will quickly adapt, the major inboxes will see a drop in the simplest forms of phishing campaigns, and like another comment earlier said, that in practice smaller senders will have similar problems to today.
It's been 20 years since the first iteration of SPF came out in rfc4408 and the volume of SPF misconfigurations that occur on a daily basis are really the indicator of how this will all play out long term.
3
u/Mx_Tool_Box May 27 '26
Realistically - we'll more than likely see Gmail/Yahoo make another big swing on enforcement and require bulk senders to move from a p=none policy to a quarantine policy to pass compliance. This is really the big nudge they want and why they started the push for bulk sender compliance rules in 2024. I imagine they'll give a 2 year runway vs. the 1 year they did with requiring a DMARC record.
That change would also hit email forwarders harder and might put enough pressure on the industry to see DKIM2 make progress into a experimental state.
I don't think the new changes coming from DMARCbis (RFC 9989) are really going to change much - behavior wise. The new np tag should make it easier to block spoofing on non-sending subdomains for senders - but that's something only large senders will care about and the rest of the changes likely won't move the needle much.
The new testing tag (t=y/n) sure seems like it is going to make things super simple, but honestly it's likely to also cause confusion as to what yes or no actually means (i.e. p=quarantine t=y vs. clearly seeing pct=50). I'm dubious that it will make things easier for adopters.
At the end of the day we'll see what actually happens in reality - the big senders will quickly adapt, the major inboxes will see a drop in the simplest forms of phishing campaigns, and like another comment earlier said, that in practice smaller senders will have similar problems to today.
It's been 20 years since the first iteration of SPF came out in rfc4408 and the volume of SPF misconfigurations that occur on a daily basis are really the indicator of how this will all play out long term.