Domain-Based Message Authentication, Reporting, and Conformance (DMARC) Failure Reporting
This specification has been revised 4 times since RFC 7489 (2015). Each document below formally obsoleted the one before it; the versions still in force are listed first.
Revision timeline
Current versions — implement against these
- RFC 9989Domain-Based Message Authentication, Reporting, and Conformance (DMARC)CurrentMay 2026proposed standard
- RFC 9990Domain-Based Message Authentication, Reporting, and Conformance (DMARC) Aggregate ReportingCurrentMay 2026proposed standard
- RFC 9991Domain-Based Message Authentication, Reporting, and Conformance (DMARC) Failure ReportingCurrentMay 2026proposed standard
Superseded versions — historical reference only
- RFC 7489Domain-based Message Authentication, Reporting, and Conformance (DMARC)ObsoletedMarch 2015informationalreplaced by RFC9989, RFC9990, RFC9991
- RFC 9091Experimental Domain-Based Message Authentication, Reporting, and Conformance (DMARC) Extension for Public Suffix DomainsObsoletedJuly 2021experimentalreplaced by RFC9989
This lineage is derived automatically from the “obsoletes” relationships recorded in the public RFC Editor index — no editorial judgement is applied to the ordering. The most recent document in the chain is RFC 9991 (May 2026).