Application Security and Permissions
DMARC: Building Open-Source Email Authentication Technologies

DMARC: Building Open-Source Email Authentication Technologies

2/1/2012 · Michael Adkins

What this post added

This post details the development and open-sourcing of DMARC (Domain-based Message Authentication, Reporting & Conformance) as a major anti-phishing effort. It explains DMARC's technical mechanism, which builds on SPF and DKIM to allow domain owners to receive reports on email authentication, audit their infrastructure, and request mailbox providers to reject unauthenticated email. The post highlights DMARC's flexibility through configurable percentages and subdomain support, and its adoption as an open specification under the Open Web Foundation Agreements. Facebook was an early adopter, publishing the first DMARC DNS records.

Read the original post ↗