7/28/2026 at 2:09:29 PM
Sadly the article doesn't really touch on whether or not DMARC accomplishes anything truly useful. When I enabled DMARC for ingress email on one of my own mail servers, it ultimately ended up regularly blocking a handful emails from customers, yet virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks.The core problem is that the real need of email end users need is a way of determining whether or not to trust a given sender. Signatures are purely a technical measure which provides no information on the trustworthiness of the sender. The end result is that email scoring still has to be content based, and the signature check technologies are pure noise with no useful signal for the purpose of determining if an email should actually show up in my inbox.
The tech industry has a bad habit of providing solutions to problems adjacent to problems the user actually needs solved while leaving the user's actual problem unresolved.
by bcrl
7/28/2026 at 2:27:00 PM
> The core problem is that the real need of email end users need is a way of determining whether or not to trust a given sender.Which is only the core problem because dmarc fixed the other core problem of figuring out who the given sender is.
DMARC does not solve everything, but it does make other solutions more effective.
by bawolff
7/29/2026 at 6:43:50 AM
> Which is only the core problem because dmarc fixed the other core problem of figuring out who the given sender is.Does it verify the sender or the domain/service which the sender is using?
by deknos
7/29/2026 at 11:20:41 AM
Yes. If an email comes from alice@gmail and validates to gmail, alice sent it.It's possible that gmail screwed up and gave Bob access to Alice's account. In this situation, though, Alice still sent it.
by inigyou
7/29/2026 at 2:35:42 PM
Google is not the only email provider in the world, though. Not all email services are global corporations, and we must be careful never to interrupt the services of independent email providers.by Freebytes
7/28/2026 at 3:35:56 PM
> virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks.This should create a means to go after the domain owners via registrar and trail of ownership, even so far as blocking email from the domain.
Forcing the spammers to pass DMARC creates a burden and an evidence trail that didn't exist before.
by brightball
7/28/2026 at 5:28:27 PM
Can we use DMARC to ask Gmail to close registrations? Google Calendar to allow far fewer people the ability to send invite notifications? Firebase to close registrations? Azure? Microsoft 365? AWS SES?It feels like the biggest spammers have swung back to just abusing SaaS and getting SPF / DKIM / DMARC for free from one of the big email providers.
by WorldMaker
7/29/2026 at 11:21:40 AM
Google now requires you to send them an SMS to open a new account. Also, Google got banned from Usenet (yes, the whole thing, yes really) because it only ever sent spam.by inigyou
7/28/2026 at 7:06:49 PM
Exactly this. Spammers have the technical competence to overcome any technical hurdle, so using evidence of technical competence achieves nothing.If it were possible to charge $0.25/email for delivery, I'd be more than happy . However, I'm sure large tech firms will need to say that is "too hard to implement at scale".
by bcrl
7/29/2026 at 12:26:47 PM
> using evidence of technical competence achieves nothingEvidence of technical competence wasn't what I was talking about. I meant that it creates a trail of evidence for police to actually pursue them, particularly in the case of phishing.
To setup DMARC, DKIM and SPF you need to control a domain. Somebody has to own that domain, unless you just hacked a DNS or somebody's already configured email server.
If you hacked it, there's a trail to contact the domain owner to notify them. If you bought it, there's a trail to find the domain owner.
You can obfuscate that with stolen cards and fake registration details, but now there's a central point where identity validation and security can concentrate itself.
A lot of positive side effects happen when the bar is raised from "any email server can send email claiming to be from anybody" to "email can only be sent claiming to be from a domain if the domain approves the sending email server."
At least when the spam concentrates from major senders like Google, etc those major senders have the means to analyze and take steps to prevent it.
by brightball
7/28/2026 at 8:01:23 PM
Stamp costs don't stop snail mail spam, either, unfortunately. I would be concerned if we added something like bitcoin fees to email delivery rather than curtail spam it would just further encourage grifters seeking ROI on their spam deliveries.by WorldMaker
7/28/2026 at 9:05:13 PM
What if a single email cost $0.001 cent to send, and it was paid to the recipient? For $10, you could send 10,000 emails. For recipients, every 1,000 emails they get is a dollar in their wallet. You’d need something like a blockchain for this to work because the traditional payment processors still haven’t figured out micropayments.by ebcode
7/29/2026 at 8:40:12 AM
> $0.001 centhttps://verizonmath.blogspot.com/2006/12/verizon-doesnt-know...
by mjmas
7/28/2026 at 9:41:20 PM
If snail mail cost $0.001 per recipient people would be getting much, much more junkmail. Likewise, if e-mail cost as much as even bulk snail mail, there'd be much less spam.Some sort of payment scheme is really the best, most durable option. The problem of mailing-lists and personal correspondence could be solved by an exclusion mechanism where the recipient effectively whitelists senders, explicitly or implicitly (e.g. whitelist a replying-sender automatically if a recipient initiates a conversation).
by wahern
7/28/2026 at 10:04:27 PM
The problem with a payment scheme is that spammers (who make money by spamming) will happily pay as a cost of doing business (or negotiate discounts/deals), but Joe User might just look at the cost and say, "you know what, maybe I'll send this as SMS instead of E-mail."So the end result will be more spam and fewer legit E-mails.
by ryandrake
7/29/2026 at 5:39:23 AM
I've wondered if it cost $10 to get through my email box the first two times what they would mean.Hormozi could charge $1,000 to get into his read box.
We could refund people, add them to a whitelist - and return a 405? payment required by default and things change in interesting ways when the amount is variable.
by stevenicr
7/29/2026 at 7:11:34 AM
There are platforms based on this idea: pay to reach a public person’s inbox, often with guaranteed responses (“guaranteed” as in “you get a response or you money back”). For example: https://mypublicinbox.com/en/by grodriguez100
7/29/2026 at 5:48:54 AM
> What if a single email cost $0.001 cent to send, and it was paid to the recipient? For $10, you could send 10,000 emails. For recipients, every 1,000 emails they get is a dollar in their wallet.I'm not sure you realize your proposal's only contribution is to worsen spam. You are unwittingly creating an incentive for email providers to lift anti-abuse filters and to maximize the volume of spam delivered to you.
by locknitpicker
7/29/2026 at 5:45:54 AM
> If it were possible to charge $0.25/email for delivery, I'd be more than happy .I'm baffled by this blend of replies. What exactly do you believe charging for an email would do? I mean, other than fabricating a revenue stream. Do you seriously believe that spam would vanish as soon as anyone charged for it's delivery? Because advertisers already pay for reaching their target audiences, and do so well beyond email.
by locknitpicker
7/28/2026 at 4:26:51 PM
They're generally hosted on a google or microsoft 365 or something slightly less shady. Good luck with that.by bigbuppo
7/28/2026 at 7:08:49 PM
What spammers are using the same domain for longer than couple of hours?What do you expect to achieve by blocking an already abandoned domain?
by illliillll
7/29/2026 at 12:10:59 AM
@gmail.com and @outlook.com are like 90% of the spam I receive. What’s missing is effective accountability for those two companies hosting persistent spam groups who operate for months unimpeded.by acdha
7/29/2026 at 11:22:20 AM
Sue the spammer, getting a subpoena from Google to find their identity.by inigyou
7/29/2026 at 11:40:12 AM
That surely is a sustainable and cost-effective alternative to Google using their trillions of dollars in resources to behave responsibly.by acdha
7/28/2026 at 3:43:00 PM
The primary purpose of DMARC is to prevent impersonation not to prevent spam. I own a domain, I implement DMARC to make sure others know when email from my domain is legitimately from my domain.by thedougd
7/28/2026 at 6:50:48 PM
Then you don't deal with email in the real world. DMARC prevents legitimate emails from people in the real world from being delivered because people make mistakes with their email systems. Passing DMARC is not a signal that the email isn't legitimate; it's merely a sign that someone correctly set up their mail server to modern standards. The email might be an impersonation, or not. There's no way to know.DMARC does absolutely nothing to prevent the kind of impersonation that occurs in the real world. It doesn't block homoglyphs or or typo-squatting or all the other forms impersonation that matter. It has failed at preventing impersonation.
Just a few days ago I had a phishing email from an elderly woman I had previously done some work for. The message passed DMARC and everything else, and the domain it was sent from was valid. But it was not legitimate; it was an impersonation of her which became obvious once the content was read.
DMARC is noise, not signal. It has to be ignored in the real world as it provides virtually no value beyond blocking emails pretty randomly because someone made a mistake when rotating their DKIM keys or one of a million other mistakes that do happen.
by bcrl
7/28/2026 at 7:08:24 PM
Okay but that doesn’t detract from the intended purpose of DMARC.by thedougd
7/28/2026 at 10:06:04 PM
Perfect example of "The Purpose Of A System Is What It Does."[1]1: https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_wha...
by ryandrake
7/29/2026 at 12:09:42 AM
That saying is bullshit. The purpose of a system is, by definition, what it is intended to do, not what it does. You can judge efficacy by the results, but not the purpose.by bigstrat2003
7/29/2026 at 11:23:07 AM
No, the entire purpose of the POSIWID principle is to refute what you just said. Do read the wikipedia page linked above. You called it out yourself when you said "by definition" - there is definition, and then there is reality, and they need not align.by inigyou
7/28/2026 at 4:31:38 PM
Isn't that the purpose of DKIM and SPF already?by HenriTEL
7/28/2026 at 4:43:31 PM
DKIM and SPF validate a message. DMARC sets a policy as to what to do with it (quarantine/reject.)by wafflebot
7/29/2026 at 11:24:50 AM
So DMARC is just advertising whether you think your SPF and DKIM are set up correctly?Seems useless to me. SPF already specifies what to do with messages that fail SPF. SPF is necessary. DKIM is questionable. DMARC is useless.
by inigyou
7/28/2026 at 4:41:51 PM
ELI5: https://www.reddit.com/r/sysadmin/comments/16gvtdj/comment/k...by warkdarrior
7/28/2026 at 9:06:16 PM
Wish I didn't have to log in to reddit to read that post. RIP useful reddit links.edit: looks like I had an extension that was redirecting to old.reddit.com, and it was old reddit that required login. Though when I turned that extension off, I got a "blocked by reddit security" error. ugggh.
by joemi
7/29/2026 at 10:29:14 AM
[–]iceph03nix655 points 2 years ago
SPF: These are the servers I will send from. If it says it's from me, but comes from somewhere else, it's likely fake
DKIM: This is my signature, if it's not on the email, it probably didn't come from my server.
DMARC: If you get mail that doesn't match the above, here's what I want you to do with it.
by justsomehnguy
7/28/2026 at 4:46:44 PM
Yes and no. DKIM signs part of the envelope to help recipients detect alteration (by verifying authenticity), SPF locks down the permissible origins for the sender. SPF is in itself imperfect and can in some situations be exploited on open-access shared systems. If the two are used in concert they offer decent protection.by daneel_w
7/28/2026 at 5:04:22 PM
Using both has to be done very carefully, because a positive result from the weaker one (SPF) will override a negative result from the stronger one (DKIM). You should maximally use DKIM and minimally use SPF. Ideally, you should not use SPF at all, but there are some senders that still don't support DKIM.by kbolino
7/28/2026 at 5:43:41 PM
Many email providers and third party security tools default settings automatically bounce or block SPF failures, no matter what DKIM says... so no, not using SPF completely is a bad idea.Using it minimally is correct, thou. Route outbound mail through as few controlled relays as possible so your SPF record only needs to list infrastructure you actually *own*, rather than growing it every time a new tool needs to send mail.
I have seen way too many clients almost hit the char limit in a TXT record
by zahrc
7/28/2026 at 6:08:16 PM
SPF failures overriding DKIM successes is a direct violation of RFC 7489 section 4.2 [1]. I have never observed such behavior in the wild, though my experience may be more limited than yours. There are two possible explanations anyway, one is that the DMARC record was missing or misconfigured, the other is that the DKIM check did not actually succeed even though you had reason to believe it should have (e.g., misaligned sender domain, invalid/stale/rotated key, etc.).I would certainly agree that DKIM is harder to get right. However, the TXT record data size limit is surmountable. You can either use EC algorithms, which have much shorter keys, or stick with e.g. RSA and its very long keys, but span them across multiple 255-byte record data chunks. That having been said, I still think DNS providers should do more to make configuring DKIM easier.
Ultimately, if you have SPF and DKIM set up such that both cover all senders, then you are just using SPF. It is the simpler and more forgiving mechanism, so its broad-scoped successes will always swallow DKIM in practice. The only reason I can think of to do this anyway is if you suspect your email provider will change IPs on you and they don't provide their own SPF record, but if that were the case, they are basically telling you not to use SPF in the first place.
EDIT: RFC 7489 was superseded by RFCs 9989-9901 rather recently. Nevertheless, the definition of success, now given in RFC 9989 section 5.3.5 [2], remains the same.
[1] = https://datatracker.ietf.org/doc/html/rfc7489#section-4.2
[2] = https://datatracker.ietf.org/doc/html/rfc9989#section-5.3.5
by kbolino
7/28/2026 at 7:27:42 PM
The "logical OR" of DMARC is absolutely a glaring caveat. I run my own MX and would personally under no circumstance omit SPF, because I consider neither SPF nor DKIM complicated enough to warrant consideration.by daneel_w
7/28/2026 at 5:06:36 PM
This is true, and yet DMARC v1 does not require you to use them in concert. Either one (a valid DKIM-signed message with sender alignment or a message that passes SPF checks with sender alignment) is enough to pass DMARC.by aaronmdjones
7/28/2026 at 4:06:55 PM
> The tech industry has a bad habit of providing solutions to problems adjacent to problems the user actually needs solved while leaving the user's actual problem unresolved.Extremely well said.
by egorfine
7/28/2026 at 2:48:00 PM
My domain is very low traffic but, I just looked through my admin email account and opendmarc has rejected 18 attempts by spammers just this past week. More were rejected by my domain's DMARC policy.by newsoftheday
7/28/2026 at 7:00:08 PM
It works at small scale when you self-select for technical competency. It does not work at larger scale when that self selection is no longer possible.My scale is that I ran an ISP for ~500 users before the network was disassembled last month. At that scale, you will encounter people that make mistakes with their email setups. When the people who make mistakes are customers which DMARC prevents delivery of emails, it is an issue as those are exactly the people for which I want to see the emails from.
I get more spam with valid SPF and DKIM via Google's own mail servers than DMARC blocks.
It says something when even gmail doesn't use DMARC as a signal that an email is valid, as gmail regularly blocks legitimate mailing list emails with completely valid signatures and non-spam content from a reputationaly sound IP.
The problem DMARC was supposed to solve (impersonation to reduce spam) isn't solved by DMARC.
by bcrl
7/28/2026 at 3:24:09 PM
My work email is Outlook, which is horribly broken and terrible to use. I have a rule configured to "re-send" all my mail to a different account where I read it with a usable MUA. Unfortunately this seems to break DMARC for external mail as now an email from e.g. user@example.com appears to have been sent by outlook.com.by SoftTalker
7/28/2026 at 3:50:09 PM
I'm not familiar with Outlook's resending, but the use case is supported if the sender uses DKIM. If the email is forwarded without changing any details, it can keep the DKIM signature. That allows the forwarded email to still pass DMARC.Now if the sender used SPF + DMARC but not DKIM, this does not work, since the sender IP can't be verified with the forwarded email. In that case, the forwarder has to change the from address to prevent the email from failing DMARC and be rejected.
In practice, senders using SPF+DMARC but not DKIM should be quite rare, you see DKIM+DMARC much more often.
by matharmin
7/28/2026 at 4:38:22 PM
I have a long-standing email address that forwards to an email system that I run. The operator of the forwarder switched to using Microsoft's mail infrastructure some years ago and the quality of service of the forward has degraded dramatically ever since.I've often seen messages resent by Microsoft's mail infrastructure with gratuitously broken DKIM signatures, generally due to changes to whitespace that are not anticipated by DKIM's message canonicalization.
I've also seen messages sent by my bank directly to the email system I administer that had broken DKIM signatures apparently due to some sort of antivirus software they had downstream of the DKIM signer.
by Polizeiposaune
7/28/2026 at 6:12:24 PM
Outlook.com also seems to routinely ignore DMARC (it will bounce emails with a DMARC that's report only)by ryanbrunner
7/28/2026 at 5:28:16 PM
I never understood the point of the anti-virus adding a message to _outgoing_ emails. Basically "I swear there is no virus in this email I'm sending you, trust me bro".by matharmin
7/28/2026 at 7:15:18 PM
"We take security seriously."by SoftTalker
7/29/2026 at 2:07:25 AM
Stopping spam isn't what DMARC was designed for.by Geezus_42
7/28/2026 at 2:32:14 PM
^ thisAdditionally, I would probably guess correctly that almost all spam comes from rotating ASNs these days. Aka from companies that do "growth marketing" or other bullshit that isn't a valid business but just... spamming people.
A lot of the domains that fall through the cracks for single-spam-campaigns have been taken over by botnet campaigns, so the actual owners of said domains probably don't know that their website is spamming everyone else.
But the major providers are the culprit, too, here. Gmail, hotmail, microsoft o365, mailgun ... they all don't even enforce SSL from server to server, and let through "sendmail" like spam because the spammers are paying customers to them.
Source: I am maintaining antispam [1] which I am using to combat spam, phishing, and malware campaigns targeting my customer networks.
by cookiengineer
7/29/2026 at 10:21:08 AM
Why would you care about TLS for spam? Are you proposing that any email sent without TLS should be label spam?by Geezus_42
7/29/2026 at 2:58:23 PM
The cheaper the relay mechanism is, the more noise/spam you'll get.Lots of servers online have a publicly exposed smtp port, where all kinds of script kiddies are just using a sendmail style email from another (not-owned) domain.
DKIM/DMARC tried to fix this (without success due to fakeable entries in the DNS records, spf=all is pretty much everywhere anyways nowadays). So my proposal for actual ownership of domain AND server infrastructure would be mutual TLS. Reverse IP lookups are broken almost always anyways, due to most hosting providers not offering real reverse DNS infrastructure that users can modify.
This way a compromised server can't send as another domain, and large-scale spamming relays that rotate ASNs would have indicators in the cert itself, which they run out of real quick due to limitations of how many IP/DNS subjects you can set in an SSL/TLS cert.
No faking and avoiding bad IP reputations by rotating ASNs anymore.
by cookiengineer
7/29/2026 at 6:05:40 PM
[flagged]by bks