
2/1/2012 · Michael Adkins
What this post added
This post details the development and open-sourcing of DMARC (Domain-based Message Authentication, Reporting & Conformance) as a major anti-phishing effort. It explains DMARC's technical mechanism, which builds on SPF and DKIM to allow domain owners to receive reports on email authentication, audit their infrastructure, and request mailbox providers to reject unauthenticated email. The post highlights DMARC's flexibility through configurable percentages and subdomain support, and its adoption as an open specification under the Open Web Foundation Agreements. Facebook was an early adopter, publishing the first DMARC DNS records.