datatracker.ietf.org
RFCs 9989, 9990, and 9991 Introduce Enhanced DMARC Reporting Mechanisms
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 28, 2026, the IETF published three RFCs (9989, 9990, and 9991) that update and enhance the Domain-based Message Authentication, Reporting, and Conformance (DMARC) protocol. RFC 9989 describes the core DMARC mechanism, allowing domain owners to specify email validation policies and request reports on email handling. RFC 9990 focuses on aggregate reports, providing domain owners with insights into the IP addresses sending emails on their behalf. RFC 9991 introduces failure reports that detail individual messages failing authentication, helping domain owners identify and address issues related to domain abuse. These updates aim to improve email security and reporting capabilities, addressing the growing problem of email spoofing and phishing. The documents collectively replace previous standards, enhancing the overall robustness of email authentication practices. The IETF community has approved these documents, reflecting a consensus on the need for improved email security measures.
Key Points: • RFCs 9989, 9990, and 9991 enhance DMARC reporting capabilities. • Aggregate and failure reports provide critical insights for domain owners. • These updates aim to combat email spoofing and improve security.