Skip to content

Email authentication standards

Biz-Ai-DMARC / Guides

Email authentication standards

SPF, DKIM and DMARC are open standards. The Internet Engineering Task Force (IETF) publishes the definitive text of each one as a Request for Comments, or RFC. Here is where each is defined, what has changed since, and where to read the source.

The source

Who writes the rules

The IETF is the open standards body behind most of the protocols the internet runs on, email included. Its specifications are published as numbered RFCs by the RFC Editor. Once published, an RFC never changes: corrections go into a new RFC that updates it, and a full replacement obsoletes it.

So the question is never just “which RFC”, but “which RFC, and what has updated it since”. The header of every RFC lists both, and the cards below do the same for the three email authentication standards.

In one line each

The core three

SPF, DKIM and DMARC

SPF

RFC 7208

Sender Policy Framework for Authorizing Use of Domains in Email, Version 1. April 2014. Proposed Standard. Replaced RFC 4408.

Defines the TXT record that lists the servers allowed to send mail for a domain, and how a receiver checks the envelope sender against it, including the 10 DNS lookup limit.

  • Updated by RFC 7372 (email authentication status codes).
  • Updated by RFC 8553 (underscored DNS names).
  • Updated by RFC 8616 (internationalized mail).

DKIM

RFC 6376

DomainKeys Identified Mail (DKIM) Signatures. September 2011. Internet Standard, the IETF’s highest maturity level.

Defines the signature a sending service adds to each message and the public key published at selector._domainkey that receivers use to verify it.

  • Updated by RFC 8301: rsa-sha1 must no longer be used to sign or verify; RSA keys must be at least 1024 bits, and 2048 bits is recommended.
  • Updated by RFC 8463: adds Ed25519 signatures.
  • Also updated by RFC 8553 and RFC 8616.

DMARC

RFC 9989

Domain-Based Message Authentication, Reporting, and Conformance (DMARC). May 2026. Proposed Standard.

Defines the _dmarc record, alignment with the visible From domain, and policy. It moved DMARC onto the IETF Standards Track and split reporting into two companion documents.

  • RFC 9990: aggregate reports (rua).
  • RFC 9991: failure reports (ruf).
  • Together they obsolete RFC 7489 (2015, Informational). RFC 9989 also absorbs the experimental public suffix extension, RFC 9091.

Around the core

Related standards

  • MTA-STS, RFC 8461 (2018, Proposed Standard): tells sending servers to deliver to yours only over verified, encrypted connections.
  • TLS reporting, RFC 8460 (2018, Proposed Standard): reports when encrypted delivery to your servers failed. Usually deployed with MTA-STS.
  • ARC, RFC 8617 (2019, Experimental): lets forwarders and mailing lists record the authentication results they saw, so mail that forwarding broke can still be judged.
  • Internationalized mail, RFC 8616 (2019, Proposed Standard): how SPF, DKIM and DMARC handle addresses and domains outside plain ASCII.

Government guidance

NIST

NIST SP 800-177 Rev. 1, Trustworthy Email

National Institute of Standards and Technology, February 2019.

Guidance for deploying SPF, DKIM and DMARC alongside TLS for mail transport and S/MIME for message content. Written for US federal agencies, and a sound checklist for anyone.

NIST Technical Note 1945, Email Authentication Mechanisms: DMARC, SPF and DKIM

National Institute of Standards and Technology, February 2017.

Describes the three mechanisms and NIST’s experience running test infrastructure for them in its High Assurance Domains project.

Both NIST documents predate the 2026 DMARC standard and cite RFC 7489. Their guidance still applies; for the record format itself, follow RFC 9989.

Reading an RFC

A few tips

  • Check the header first. “Obsoleted by” means read the newer document instead; “Updated by” means read both.
  • MUST, SHOULD and MAY are defined terms. RFC 2119 and RFC 8174 set their meaning: MUST is a requirement, SHOULD is a strong recommendation with room for good reasons.
  • Look at the errata. The RFC Editor keeps a list of confirmed corrections for each RFC, linked from its page.
  • Mind the status. Internet Standard and Proposed Standard are on the Standards Track; Informational and Experimental are not. DMARC was Informational until RFC 9989.

Our guides follow the current documents: DMARC record tags and DMARC alignment are written to RFC 9989, and SPF record syntax to RFC 7208.

Keep reading

More guides and free tools

Guides

Free tools

Tell us what is not working

A 30-minute call, no pitch deck. We will tell you what we would do first, and whether we are the right people to do it.

Powered by Hostinger

This site is hosted on Hostinger. Some links here are affiliate links and may earn us a commission at no extra cost to you. We recommend only what we use ourselves or built ourselves. Read the full disclosure.