DMARC has been public since 2012 but most company domains still don't enforce it
- Security
- Infrastructure
- Developer Tools
The post says DMARC has been public since 2012, yet most company domains still do not enforce it. The basic claim landed with people who run mail in the real world. They pointed to the same blockers over and over: small teams do not have time to inventory every tool that sends mail, DMARC reports arrive as useless compressed XML unless you add more tooling, and third party platforms still break or omit DKIM in ways that make enforcement risky. A lot of domains also likely never intended to use email at all, which muddies adoption stats unless you separate active mail domains from everything else.
If you run a domain, publish a strict DMARC policy for domains that do not send mail and audit every service that does before moving active domains from p=none to reject. Do not expect DMARC to clean up spam by itself. Focus just as hard on provider abuse handling, forwarding behavior, and your actual sending reputation.
-
ciphercue.com
- Discuss on HN