A brief history of DMARC

From early sender–receiver collaboration to DMARC 2.0: the protocol milestones, provider policies, industry standards and scoped government requirements that changed how domains protect email.

These authority types are deliberately separate. A mailbox-provider delivery policy, an industry standard and a government mandate do not impose the same obligations.
Filter DMARC history by authority type
  1. Protocol & engineering

    DMARC 2.0 reaches the Standards Track

    RFC 9989, RFC 9990 and RFC 9991 replace the original DMARC RFC with Proposed Standards for the core protocol, aggregate reporting and failure reporting. The revision introduces DNS Tree Walk discovery and separates reporting so each part can evolve independently.

    DMARC 2.0IETFProposed Standard
  2. Mailbox-provider policy
  3. Public-sector mandate

    Denmark requires rejection policy for state authorities

    Denmark’s updated technical minimum requirements direct state authorities to publish DMARC at p=reject on authority-owned main domains and subdomains, alongside SPF and DKIM controls. The scope is Danish state authorities, not every Danish organisation.

    DenmarkGovernmentp=reject
  4. Mailbox-provider policy

    Outlook.com introduces high-volume sender requirements

    Microsoft requires domains sending more than 5,000 messages a day to Outlook.com consumer services to pass SPF and DKIM and publish aligned DMARC at p=none or stronger. Its update says non-compliant mail initially goes to Junk; a permanent-rejection date was not announced.

    MicrosoftOutlook.com5,000/day
  5. Industry standard
  6. Mailbox-provider policy

    Apple publishes current iCloud bulk-sender guidance

    Apple’s iCloud Mail guidance says bulk senders must use SPF and DKIM and publish a DMARC policy; failure to meet all listed requirements can result in rejection. Apple does not publish a numeric bulk threshold or require a policy stronger than publishing DMARC.

    AppleiCloud MailBulk senders
  7. Industry standard
  8. Mailbox-provider policy
  9. Mailbox-provider policy

    Google and Yahoo announce stronger sender rules

    Google defines a bulk sender as one sending about 5,000 or more messages to personal Gmail accounts in 24 hours. Yahoo announces comparable authentication expectations but deliberately publishes no numeric threshold, so Google’s number must not be applied to Yahoo.

    GoogleYahooAnnouncement
  10. Industry standard
  11. Protocol & engineering
  12. Protocol & engineering
  13. Industry standard
  14. Public-sector mandate
  15. Public-sector mandate
  16. Protocol & engineering

    IETF documents DMARC’s indirect-mail limitation

    RFC 7960 explains how forwarding, mailing lists and other indirect flows can break SPF or DKIM alignment and therefore DMARC. It establishes the technical case for measured policy rollout rather than an indiscriminate jump to p=reject.

    RFC 7960Mailing listsInteroperability
  17. Public-sector mandate
  18. Protocol & engineering
  19. Protocol & engineering

    DMARC’s first standards path takes shape

    The DMARC specification is circulated as an Internet-Draft in March 2013 and moves to the Independent Submissions track in April 2014. That route determines the Informational status of the first RFC.

    Internet-DraftIndependent SubmissionStandards history
  20. Protocol & engineering
  21. Protocol & engineering
Method and scope. Dates distinguish announcements, publication and enforcement where the source permits. Provider guidance can change in place, and public-sector requirements are shown only within their stated jurisdiction. This chronology does not turn guidance or example controls into universal legal mandates.