What DMARC Protects You From, and What It Does Not
The DMARC email authentication protocol is often misunderstood as a comprehensive security solution against phishing and spam. This article clarifies that DMARC only verifies domain ownership and authorization, and should be used alongside other security controls.
Why it matters
Misunderstanding DMARC's limitations can lead organizations to believe they are protected from phishing when they remain vulnerable to other attack vectors.
DMARC gets asked to do a lot of jobs it was never designed for. Teams reach for it as a spam filter, a phishing filter, and a general trust signal. It is none of those. The current DMARC protocol, defined in RFC 9989 , answers a deliberately narrow question: did the owner of the domain in the visible From address authorise this message, and can that authorisation be established through an aligned SPF or DKIM result?
That question is worth answering. It is also much narrower than the reputation DMARC has picked up. Getting the boundary right matters, because a team that reaches p=reject believing they are now phishing-proof will skip the controls that cover everything DMARC leaves untouched.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in