Biz-Ai-DMARC / Guides
DMARC glossary
The words that come up in DMARC records, reports and vendor documentation, in plain language.
A to Z
Terms
Aggregate report (rua)
A daily summary a receiver sends to the rua address: every IP that sent as your domain, how many messages, and the SPF, DKIM and DMARC results. XML, usually compressed. Defined in RFC 9990.
Alignment
The requirement that the domain SPF or DKIM checked matches the domain in the visible From address. See DMARC alignment.
ARC
Authenticated Received Chain. Lets a forwarder or mailing list record the checks it saw on arrival, so the final receiver can trust mail that forwarding broke.
BIMI
Brand Indicators for Message Identification. Shows your logo next to authenticated mail. Requires an enforced DMARC policy, and most large inboxes also require a mark certificate.
DKIM
DomainKeys Identified Mail. A cryptographic signature added by the sending service, verified with a public key published in your DNS.
DKIM selector
The name that tells receivers which of your DKIM keys to fetch, as in selector._domainkey.example.com. Each sending service usually has its own.
DMARC
Domain-based Message Authentication, Reporting and Conformance. Ties SPF and DKIM to the visible From domain, sets a policy for failures and requests reports. Current standard: RFC 9989.
Disposition
What the receiver actually did with a message: delivered (none), quarantined or rejected. Shown per row in aggregate reports.
Envelope sender
The hidden address used for bounces, also called the Return-Path or MAIL FROM. SPF checks this domain, not the visible From.
Failure report (ruf)
A report about a single failing message, sent to the ruf address. Also called a forensic report. Few receivers send them. Defined in RFC 9991.
Forwarder
A service that passes mail on, such as a forwarding address or an alumni mailbox. Forwarding breaks SPF; DKIM usually survives.
Header From
The From address the recipient sees. It is the domain DMARC protects.
MTA-STS
A policy that tells sending servers to deliver to your mail servers only over verified, encrypted connections.
Organizational domain
The domain you registered, such as example.com, as opposed to its subdomains. Relaxed alignment compares at this level.
Permerror and temperror
SPF or DKIM results meaning a permanent problem with the record (such as more than 10 lookups) or a temporary DNS failure.
Policy (p)
What you ask receivers to do with mail that fails DMARC: none, quarantine or reject.
Quarantine
Treat as suspicious, which in practice means the spam or junk folder.
Receiver
The mail system that accepts a message and applies SPF, DKIM and DMARC checks. Large receivers also send the reports.
Reject
Refuse the message during delivery. The strongest DMARC policy, and the goal of a rollout.
Reporting organization
The receiver that sent a given aggregate report, named at the top of the report.
RFC 9989
The DMARC standard published in May 2026, replacing RFC 7489 from 2015. Added the np and t tags and removed pct, rf and ri.
Softfail
The SPF result of ~all: probably not authorized. DMARC counts anything other than an SPF pass as a failure, so a softfail never helps a message pass DMARC.
SPF
Sender Policy Framework. A DNS record listing the servers allowed to send for your domain. See SPF record syntax.
SPF lookup limit
An SPF check may make at most 10 DNS lookups. More than that is a permerror, and SPF fails for all mail.
Spoofing
Sending mail that claims to come from a domain the sender does not control. DMARC at reject stops exact-domain spoofing.
Subdomain policies (sp, np)
sp sets the policy for existing subdomains; np for subdomains that do not exist. Both default to the main policy.
Test mode (t)
With t=y, receivers apply your policy one step softer. Replaced pct in RFC 9989.
TLS-RPT
TLS reporting. Receivers of your outbound mail report when encrypted delivery to your servers failed. Often deployed with MTA-STS.
TXT record
A DNS record that holds text. SPF, DKIM keys and DMARC are all published as TXT records.
Keep reading
More guides and free tools
Guides
- DMARC record tags: Every tag in a DMARC record, what it does and what to set it to.
- DMARC alignment: Why passing SPF or DKIM is not enough, and relaxed versus strict.
- SPF record syntax: Mechanisms, qualifiers and the 10 DNS lookup limit.
- Email authentication standards: The IETF documents that define SPF, DKIM and DMARC, with links to the source.
Free tools
- DMARC record generator: build a record for the current standard.
- DMARC report viewer: read an aggregate report as a table, in your browser.
- Biz-Ai-DMARC: reports collected, summarized and alerted on for you.
Tell us what is not working
A 30-minute call, no pitch deck. We will tell you what we would do first, and whether we are the right people to do it.