RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 9989, RFC 9990, RFC 9991.
Current document in this lineage: RFC 9989 — Domain-Based Message Authentication, Reporting, and Conformance (DMARC); RFC 9990 — Domain-Based Message Authentication, Reporting, and Conformance (DMARC) Aggregate Reporting; RFC 9991 — Domain-Based Message Authentication, Reporting, and Conformance (DMARC) Failure Reporting
In plain English — editorial summary, not part of the RFC
Domain-based Message Authentication, Reporting, and Conformance (DMARC) is a scalable mechanism by which a mail-originating organization can express domain-level policies and preferences for message validation, disposition, and reporting, that a mail-receiving organization can use to improve mail handling. Originators of Internet Mail need to be able to associate reliable and authenticated domain identifiers with messages, communicate policies about messages that use those identifiers, and report about mail using those identifiers. These abilities have several benefits: Receivers can provide feedback to Domain Owners about the use of their domains; this feedback can provide valuable insight about the management of internal operations and the presence of external domain name abuse. DMARC does not produce or encourage elevated delivery privilege of authenticated email. DMARC is a mechanism for policy distribution that enables increasingly strict handling of messages that fail authentication checks, ranging from no action, through altered delivery, up to message rejection.
Document record
- Document ID
- RFC7489
- Published
- March 2015
- Authors
- M. Kucherawy; E. Zwicky
- Status
- INFORMATIONAL
- Stream
- INDEPENDENT
- Area
- —
- Pages
- 73
- Also known as
- —
Topics
Standards lineage
This document is one revision in a chain of 5 RFCs, each formally replacing the one before it.
Referenced by
5 later RFCs formally update or obsolete part of this document.
- RFC 8553DNS Attrleaf Changes: Fixing Specifications That Use Underscored Node NamesCurrent
March 2019
- RFC 8616Email Authentication for Internationalized MailCurrent
June 2019
- RFC 9989Domain-Based Message Authentication, Reporting, and Conformance (DMARC)Current
May 2026
- RFC 9990Domain-Based Message Authentication, Reporting, and Conformance (DMARC) Aggregate ReportingCurrent
May 2026
- RFC 9991Domain-Based Message Authentication, Reporting, and Conformance (DMARC) Failure ReportingCurrent
May 2026
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9057Email Author Header FieldCurrent
June 2021
- RFC 7073A Reputation Response Set for Email IdentifiersCurrent
November 2013
- RFC 7072A Reputation Query ProtocolCurrent
November 2013
- RFC 7071A Media Type for Reputation InterchangeCurrent
November 2013
- RFC 7070An Architecture for Reputation ReportingCurrent
November 2013
- RFC 5672RFC 4871 DomainKeys Identified Mail (DKIM) Signatures -- UpdateObsoleted
August 2009
- RFC 7601Message Header Field for Indicating Message Authentication StatusObsoleted
August 2015
- RFC 7001Message Header Field for Indicating Message Authentication StatusObsoleted
September 2013
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?