emailmarketing.net

Learn / Authentication · 13 articles

Authentication

If you only read one

SPF (Sender Policy Framework)

RFC 7208 reference — record syntax (mechanisms, qualifiers, modifiers, macros), the check_host() evaluation algorithm, DNS lookup limits, result codes, and common pitfalls. 6 min

  1. SPF (Sender Policy Framework)

    RFC 7208 reference — record syntax (mechanisms, qualifiers, modifiers, macros), the check_host() evaluation algorithm, DNS lookup limits, result codes, and common pitfalls.

    Reference

    6 min

  2. DKIM (DomainKeys Identified Mail)

    RFC 6376 reference plus RFC 8301 (rsa-sha256 required, 1024–4096-bit keys) and RFC 8463 (ed25519-sha256) — signature and key record syntax, tag meanings, canonicalization, signing scope, and risks.

    Reference

    6 min

  3. DKIM Key Rotation

    M3AAWG DKIM Key Rotation BCP (rev. March 2019) — semiannual rotation cadence, selector naming schemes, the two-live-keys workflow, p= retirement, CNAME/subdomain delegation for third parties, and rotation auditing.

    Operational

    7 min

  4. DKIM Replay Attacks

    The DKIM replay problem (draft-ietf-dkim-replay-problem) — how one legitimately signed message gets resent to millions, why l=/x= don't fix it, current mitigations and their tradeoffs, and what it means for ESP infrastructure.

    Foundational

    6 min

  5. DKIM2 (in-progress IETF work)

    The IETF DKIM WG redesign of DKIM — per-hop chained signatures bound to the SMTP envelope, documented modifications ("recipes"), authenticated bounces, replay resistance — with WG status as of July 2026. NOT a published standard.

    Foundational

    8 min

  6. DMARC (Domain-based Message Authentication, Reporting, and Conformance)

    What DMARC does and doesn't do, how it builds on SPF and DKIM, domain alignment, the DNS record, and choosing a handling policy.

    Operational

    5 min

  7. DMARC Deployment in Depth

    Operational DMARC deployment — full tag reference, subdomain policy, pct sampling, alignment strictness, report processing, forwarding/mailing-list failure modes, and the none→quarantine→reject rollout.

    Operational

    8 min

  8. DMARC Standard Reference (RFC 9989 / DMARCbis)

    The standards-track DMARC spec that obsoletes RFC 7489 — full record tag registry, the DNS Tree Walk replacing the Public Suffix List, alignment rules, policy discovery, and what changed.

    Reference

    4 min

  9. DMARC Aggregate Reports (RFC 9990)

    The XML aggregate feedback format — report structure, transport, filename and subject conventions, external-destination verification, and policy-override reasons.

    Reference

    4 min

  10. DMARC Failure Reports (RFC 9991)

    Per-message DMARC failure ("forensic") reports — ARF format, required fields, the ruf/fo tags, privacy constraints, and why few providers send them.

    Reference

    3 min

  11. ARC (Authenticated Received Chain)

    RFC 8617 reference — the three ARC header fields, instance and chain-validation tags, sealing and validation rules, and how receivers use an intact chain to override DMARC failures caused by forwarding.

    Reference

    5 min

  12. The Authentication-Results Header

    RFC 8601 reference — syntax of the header receivers use to record SPF/DKIM/DMARC/iprev results, ptypes and properties, method result codes, and how to read one.

    Reference

    3 min

  13. BIMI (Brand Indicators for Message Identification)

    Implementing BIMI — DMARC enforcement prerequisites, the BIMI DNS record, SVG Tiny PS logo requirements, VMC/CMC certificates, and mailbox-provider support.

    Operational

    4 min