DMARC (Domain-based Message Authentication, Reporting and Conformance)
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a standard for authenticating emails. The aim is to give receiving servers clear rules on how to handle messages that do not clearly match the sender domain. DMARC builds on SPF and DKIM and helps organizations to control spoofing, phishing and brand abuse significantly better.
Technically, DMARC checks whether a message passes a valid SPF or DKIM check and whether the domain used in the process matches the visible sender address (alignment). The domain owner specifies via a DNS policy how recipients should handle failed checks: deliver (none), move to quarantine (quarantine) or reject (reject). Aggregated reports additionally provide insight into who is sending emails on behalf of the domain – the basis for cleanly integrating service providers and detecting misuse.
A cleanly implemented DMARC strategy frequently also improves the deliverability of legitimate emails. For marketing, IT and security, DMARC is thus a shared topic – especially where many systems, service providers or applications send emails on behalf of the organization.