Biz-Ai-DMARC / Guides
Email authentication standards
SPF, DKIM and DMARC are open standards. The Internet Engineering Task Force (IETF) publishes the definitive text of each one as a Request for Comments, or RFC. Here is where each is defined, what has changed since, and where to read the source.
The source
Who writes the rules
The IETF is the open standards body behind most of the protocols the internet runs on, email included. Its specifications are published as numbered RFCs by the RFC Editor. Once published, an RFC never changes: corrections go into a new RFC that updates it, and a full replacement obsoletes it.
So the question is never just “which RFC”, but “which RFC, and what has updated it since”. The header of every RFC lists both, and the cards below do the same for the three email authentication standards.
The core three
SPF, DKIM and DMARC
SPF
RFC 7208
Sender Policy Framework for Authorizing Use of Domains in Email, Version 1. April 2014. Proposed Standard. Replaced RFC 4408.
Defines the TXT record that lists the servers allowed to send mail for a domain, and how a receiver checks the envelope sender against it, including the 10 DNS lookup limit.
DKIM
RFC 6376
DomainKeys Identified Mail (DKIM) Signatures. September 2011. Internet Standard, the IETF’s highest maturity level.
Defines the signature a sending service adds to each message and the public key published at selector._domainkey that receivers use to verify it.
DMARC
RFC 9989
Domain-Based Message Authentication, Reporting, and Conformance (DMARC). May 2026. Proposed Standard.
Defines the _dmarc record, alignment with the visible From domain, and policy. It moved DMARC onto the IETF Standards Track and split reporting into two companion documents.
Around the core
Related standards
Government guidance
NIST
NIST SP 800-177 Rev. 1, Trustworthy Email
National Institute of Standards and Technology, February 2019.
Guidance for deploying SPF, DKIM and DMARC alongside TLS for mail transport and S/MIME for message content. Written for US federal agencies, and a sound checklist for anyone.
NIST Technical Note 1945, Email Authentication Mechanisms: DMARC, SPF and DKIM
National Institute of Standards and Technology, February 2017.
Describes the three mechanisms and NIST’s experience running test infrastructure for them in its High Assurance Domains project.
Both NIST documents predate the 2026 DMARC standard and cite RFC 7489. Their guidance still applies; for the record format itself, follow RFC 9989.
Reading an RFC
A few tips
- Look at the errata. The RFC Editor keeps a list of confirmed corrections for each RFC, linked from its page.
- Mind the status. Internet Standard and Proposed Standard are on the Standards Track; Informational and Experimental are not. DMARC was Informational until RFC 9989.
Our guides follow the current documents: DMARC record tags and DMARC alignment are written to RFC 9989, and SPF record syntax to RFC 7208.
Keep reading
More guides and free tools
Guides
- DMARC record tags: Every tag in a DMARC record, what it does and what to set it to.
- DMARC alignment: Why passing SPF or DKIM is not enough, and relaxed versus strict.
- SPF record syntax: Mechanisms, qualifiers and the 10 DNS lookup limit.
- DMARC glossary: The terms used in records and reports, in plain words.
Free tools
- DMARC record generator: build a record for the current standard.
- DMARC report viewer: read an aggregate report as a table, in your browser.
- Biz-Ai-DMARC: reports collected, summarized and alerted on for you.
Tell us what is not working
A 30-minute call, no pitch deck. We will tell you what we would do first, and whether we are the right people to do it.