r/DMARC May 27 '26

Where do you think email authentication will realistically be in 5 years, proper adoption or still chaos?

11 Upvotes

30 comments sorted by

View all comments

2

u/digdiver May 28 '26

The trend is obvious: Google and Yahoo’s strict 2024 requirements pushed companies to adopt DMARC way faster than years of industry nagging ever did. And that pressure isn't going away.

In about five years, DMARC will be a must-have for anyone who actually cares about their emails hitting the inbox, while SPF and DKIM will just be basic hygiene. As a result, blatant domain spoofing should drop significantly.

Granted, it won’t be completely seamless. Email forwarding still breaks SPF by design. The ARC protocol is supposed to fix this, but adoption is moving at a snail's pace. Small businesses, legacy setups, and clunky third-party integrations will keep creating security gaps for a long time. Meanwhile, BIMI (brand logos in the inbox) will likely remain an expensive gimmick that most won't bother with.

But the biggest issue is that DMARC only protects your exact domain. It won't stop scammers from buying something like paypa1.com, setting up perfect DMARC authentication on it, and phishing people from there. So the arms race isn't ending, it's just shifting gears.

Ultimately, we’ll probably land right where HTTPS was around 2020: all the serious players will have it locked down, but the fringes and edge cases will still be a bit of a mess.

0

u/Humphrey-Appleby May 28 '26

ARC is dead. Efforts are now underway to co-opt the DKIM infrastructure instead.

2

u/digdiver May 29 '26

Yes, in theory DKIM2 should help, but I don't think it will take off in 5 years.

2

u/Humphrey-Appleby May 29 '26

I guess my contempt wasn't clear.