Category

Authentication Standards

Every update we have filed under Authentication Standards. 2 entries and counting - newest first.

2026
28

DMARCbis Is Now RFC 9989: What Actually Changed, and the t= Trap Everyone Is Getting Wrong

DMARCbis stopped being a draft in May 2026: it is now RFC 9989 (core), 9990 (aggregate reporting) and 9991 (failure reporting), and it obsoletes the original RFC 7489 that almost every DMARC guide still cites. The record you publish keeps working, but three things changed under the hood - the Public Suffix List is replaced by a DNS tree walk, pct/rf/ri are removed, and a new np= tag is the sharpest anti-spoofing control in the record. Watch out for t=: it steps your policy down one level, it does not disable it, and secondary sources are already calling it pct=0 by mistake.

EffectivePublished May 2026

Read the full briefing
dmarcbisrfc-9989dmarcauthentication
5

DKIM2: Email Signing Gets a Ground-Up Rebuild to Stop Replay and Survive Forwarding

A revived IETF working group is rebuilding DKIM from the ground up. DKIM2 (draft-ietf-dkim-dkim2-spec, authored by engineers from Yahoo, Google and Fastmail) signs every hop, binds each signature to the SMTP envelope to stop replay, records reversible "recipes" so forwarding no longer breaks DMARC, and routes provable bounces up the chain - and a companion draft retires ARC into it. It is real enough to watch (working code exists), but still a draft: do not deploy it in production yet.

Read the full briefing
dkim2ietf-draftauthentication
Chat with us!