HN
Today

DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It

DMARC, the decade-old email authentication standard, is still unenforced by 68.4% of domains, despite its critical role in combating spoofing. This article meticulously breaks down the widespread p=none policy and the challenges in interpreting aggregate reports. Hacker News commenters widely debate DMARC's practical effectiveness, lament the complexity of email security, and point fingers at major email providers for exacerbating the problem.

47
Score
35
Comments
#8
Highest Rank
8h
on Front Page
First Seen
Jul 28, 1:00 PM
Last Seen
Jul 28, 8:00 PM
Rank Over Time
17981314181921

The Lowdown

The article highlights that despite DMARC (Domain-based Message Authentication, Reporting, and Conformance) being available since 2012, a significant majority of domains—68.4% of those surveyed—either lack a DMARC record or fail to enforce any policy. This enforcement gap leaves many organizations vulnerable to email spoofing and makes it harder to trust email as a communication channel.

  • Low Enforcement: 45.1% of domains checked lack a DMARC record, and an additional 23.3% of the total use a p=none policy, which only monitors and doesn't instruct mail servers to quarantine or reject unauthenticated emails.
  • p=none Persistence: The p=none policy, intended for temporary monitoring, has become a permanent state for many due to the complexity of identifying legitimate email senders from fragmented rua= aggregate reports.
  • Reporting Fragmentation: DMARC reports often contain obscure, one-off email addresses rather than clearly identifiable vendors, turning enforcement into a deprioritized "research task, not a configuration change."
  • DMARC Monitoring Landscape: While some dedicated DMARC monitoring services exist, many rua= reports are directed to transactional email platforms (like Brevo, Postmark) where they are a side effect of sending mail, not a dedicated security product.
  • International Discrepancies: DMARC enforcement varies by country, with the UK and US showing higher p=reject rates, while countries like Italy have low no-record rates but high p=none usage.
  • Adjacent Controls: Adoption of related email security controls like BIMI and MTA-STS remains very low (2.6% and 1.4% respectively), with DNSSEC showing 0% validation in the author's strict check.
  • RFC Updates: DMARC's core specification recently gained formal IETF standard status (RFC 9989), replacing the older informational RFC 7489, though practical changes for existing tags are minimal.
  • Compliance vs. DMARC: Neither SOC 2 nor ISO 27001 explicitly mandates DMARC, though it can be part of broader risk-based controls.
  • Real-world Example: The UK food producer Cranswick (cranswick.co.uk) illustrates the p=none problem, with multiple, disparate rua= report destinations making it challenging to reconcile who is actually sending mail.

The central argument is that the inherent complexity of processing DMARC aggregate reports, rather than simple inertia or ignorance, is the primary reason for the enduring p=none problem, significantly hindering widespread enforcement and leaving email communication vulnerable.

The Gossip

DMARC Doubts & Deployment Dilemmas

Many users expressed frustration with DMARC's real-world effectiveness, noting it often blocks legitimate emails while spammers adapt. Some, particularly self-hosters, found the reports unhelpful or too complex to manage, leading them to disable DMARC entirely. Conversely, advocates highlight its crucial role in preventing domain spoofing, reducing backscatter spam, and helping emails avoid spam folders, arguing that its complexity is a necessary challenge for better email security. The difficulty of implementation, especially with subdomains and conflicting guides, is a common pain point.

Corporate Control & Community Calls

A significant thread criticizes major email providers (Google, Microsoft, Amazon) for their perceived monopolistic control over email, alleging they ignore abuse reports and penalize small, legitimate senders while enabling spammers who are paying customers. Commenters argue that email has become a "by-the-corporation, for-the-corporation" service, leading some to call for a "Community Email Initiative" or advocate for self-hosting to reclaim trust and autonomy, despite the inherent challenges like emails landing in spam due to low volume.

Authentication Adoption Obstacles

Discussion revolves around the barriers to broader DMARC adoption, particularly the burden it places on smaller organizations without dedicated resources. Many find the `rua=` reports overwhelming and difficult to interpret, turning enforcement into a deprioritized "research task." While some acknowledge that DMARC helps solve the problem of identifying senders, the struggle to get SPF and DKIM correctly configured often delays DMARC implementation. The absence of MX records for some domains also raises questions about the true "email-relevant" population.