Article may be outdated

This article is 58 days old. Some details may have changed since publication.

Hacker News·4 min read·medium

What DMARC Protects You From, and What It Does Not

A
adulion
✦AI Summary

The DMARC email authentication protocol is often misunderstood as a comprehensive security solution against phishing and spam. This article clarifies that DMARC only verifies domain ownership and authorization, and should be used alongside other security controls.

Why it matters

Misunderstanding DMARC's limitations can lead organizations to believe they are protected from phishing when they remain vulnerable to other attack vectors.

✦Dive DeeperCreate a free account to unlock

DMARC gets asked to do a lot of jobs it was never designed for. Teams reach for it as a spam filter, a phishing filter, and a general trust signal. It is none of those. The current DMARC protocol, defined in RFC 9989 , answers a deliberately narrow question: did the owner of the domain in the visible From address authorise this message, and can that authorisation be established through an aligned SPF or DKIM result?

That question is worth answering. It is also much narrower than the reputation DMARC has picked up. Getting the boundary right matters, because a team that reaches p=reject believing they are now phishing-proof will skip the controls that cover everything DMARC leaves untouched.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technology
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in