I’m a DMARC fan. Are you?


Based on this totally scientific, absolutely guaranteed to be accurate poll that I ran on Linkedin for the past week or so, DMARC is almost universally loved.

A couple of people got a bit snarky in the comments, pointing out the “social media effect” and that this was like asking if people like air or water. Well, duh (mostly). This clearly isn’t a scientific survey. People following me on Linkedin are more likely to be aligned with my thoughts on DMARC, which is that it’s a valuable part of protecting domains against phishing and spoofing.

But still, y’all would be surprised. There are some people out there who don’t like DMARC. Quite possibly for legitimate reasons, at least from their own perspective. And this isn't a new thing. Going back all the way to when Yahoo first implemented a DMARC policy of p=reject in 2014, some folks were very upset about the impact this had on email discussion lists. (But, as I said in 2015, we survived.)

One of the big beefs initially is that it was unfair to change how email forwarding and mailing lists in a way that fails those messages without changes being made by email administrators and server owners. I always understood the complaint. But I strongly felt that this ship had long already sailed. Open relaying mail servers, spam abuse, and bad actors drove us to implement IP blocklists way back in the mid-to-late 1990s, and some of the complaints were very similar. People were very upset that they were being asked to update how their servers worked if they wanted to continue to see their legitimate email delivered.

Point being, it was a new concept circa 1997. By 2015, not so much. DMARC pretty firmly found itself embedded into email sender best practices and mailbox provider requirements, and remains so today. Yet there are still some folks who don’t like DMARC today and want it to go away. I’m not one of those folks. I really do see the value in it.

What do you think?
Post a Comment

Comments