Industry Updates

The email deliverability signal log

A running record of the changes that move the inbox: mailbox-provider policy shifts, new authentication standards, privacy and legal rules, blacklist and reputation news, and the acquisitions reshaping the space. Each entry is dated, rated for impact, and written to answer one question - what changed, and what should you do about it.

2026
28

DMARCbis Is Now RFC 9989: What Actually Changed, and the t= Trap Everyone Is Getting Wrong

DMARCbis stopped being a draft in May 2026: it is now RFC 9989 (core), 9990 (aggregate reporting) and 9991 (failure reporting), and it obsoletes the original RFC 7489 that almost every DMARC guide still cites. The record you publish keeps working, but three things changed under the hood - the Public Suffix List is replaced by a DNS tree walk, pct/rf/ri are removed, and a new np= tag is the sharpest anti-spoofing control in the record. Watch out for t=: it steps your policy down one level, it does not disable it, and secondary sources are already calling it pct=0 by mistake.

EffectivePublished May 2026

Read the full briefing
dmarcbisrfc-9989dmarcauthentication
14
Transport SecurityMedium impact

TLS certificate lifetimes: 200 days now, 100 in 2027, 47 by 2029

CA/B Forum ballot SC-081v3 is phasing public TLS certificate validity down from 398 days to 47 by March 2029 - the 200-day cap took effect 15 March 2026. Email surfaces are on the clock: MX/STARTTLS, the MTA-STS policy host, BIMI logo hosting. The first mass renewal wave of 200-day certificates lands around 1 October 2026.

EffectiveIn force since 15 Mar 2026 - next step 15 Mar 2027

Read the full briefing
tlscertificatescab-forummta-ststls-rpt
9
DeliverabilityMedium impact

APRF: The Draft Standard That Would Finally Show Senders Where Their Mail Lands

A new IETF draft (draft-brotman-aggregate-performance-reporting) proposes a DMARC-style mechanism for mailbox providers to email senders daily JSON reports on inbox placement and engagement - keyed to the DKIM signing domain, not the From address. It is early (Comcast is the only provider sending beta reports, with a Google engineer among the authors), but it could finally standardize the placement data that has always lived behind per-provider portals.

Read the full briefing
aprfietf-draftreporting
5

DKIM2: Email Signing Gets a Ground-Up Rebuild to Stop Replay and Survive Forwarding

A revived IETF working group is rebuilding DKIM from the ground up. DKIM2 (draft-ietf-dkim-dkim2-spec, authored by engineers from Yahoo, Google and Fastmail) signs every hop, binds each signature to the SMTP envelope to stop replay, records reversible "recipes" so forwarding no longer breaks DMARC, and routes provable bounces up the chain - and a companion draft retires ARC into it. It is real enough to watch (working code exists), but still a draft: do not deploy it in production yet.

Read the full briefing
dkim2ietf-draftauthentication
Chat with us!