RFCs 9989, 9990, and 9991 Introduce Enhanced DMARC Reporting Mechanisms

RFCs 9989, 9990, and 9991 Introduce Enhanced DMARC Reporting Mechanisms

First seen 28 Jul 2026, 13:36 UTC datatracker.ietf.org 92% similarity 24.9

Article Content

Browse articles
ThreatCluster

On July 28, 2026, the IETF published three RFCs (9989, 9990, and 9991) that update and enhance the Domain-based Message Authentication, Reporting, and Conformance (DMARC) protocol. RFC 9989 describes the core DMARC mechanism, allowing domain owners to specify email validation policies and request reports on email handling. RFC 9990 focuses on aggregate reports, providing domain owners with insights into the IP addresses sending emails on their behalf. RFC 9991 introduces failure reports that detail individual messages failing authentication, helping domain owners identify and address issues related to domain abuse. These updates aim to improve email security and reporting capabilities, addressing the growing problem of email spoofing and phishing. The documents collectively replace previous standards, enhancing the overall robustness of email authentication practices. The IETF community has approved these documents, reflecting a consensus on the need for improved email security measures.

Key Points: • RFCs 9989, 9990, and 9991 enhance DMARC reporting capabilities. • Aggregate and failure reports provide critical insights for domain owners. • These updates aim to combat email spoofing and improve security.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
RFCs 9989, 9990, and 9991 published
The IETF released three RFCs enhancing DMARC, focusing on validation policies and reporting mechanisms.
datatracker.ietf.org
2026-07-28
RFC 9989 details DMARC mechanism
RFC 9989 describes how domain owners can publish policies and request reports for email validation.
datatracker.ietf.org
2026-07-28
RFC 9990 introduces aggregate reports
RFC 9990 allows domain owners to receive XML-based aggregate reports from mail receivers.
datatracker.ietf.org
2026-07-28
RFC 9991 specifies failure reports
RFC 9991 outlines the structure and purpose of failure reports for messages that fail DMARC authentication.
datatracker.ietf.org

Community

Browse all →