Z
ZoneSanity Console v1.3.0
IETF RFC 7489 Standard • Email Authentication Policy

Gradual DMARC Deployment Roadmap Without Service Interruption (RFC 7489)

Published by ZoneSanity Technical Engineering • IETF RFC 7489 Specification

1. DMARC Architecture & The Concept of Domain Alignment

DMARC (Domain-based Message Authentication, Reporting, and Conformance), standardized in IETF RFC 7489, unifies SPF validation (RFC 7208) and DKIM cryptographic signatures (RFC 6376) under a single enterprise security policy.

DMARC addresses the historical vulnerability in the SMTP protocol where the visible RFC 5322 From: header displayed to end users was decoupled from the authenticated transport identity (Return-Path or DKIM signing domain). To satisfy a DMARC policy check, a message must achieve Domain Alignment across at least one underlying authentication mechanism.

2. Relaxed vs. Strict Domain Alignment Modes

RFC 7489 allows domain owners to configure the strictness of alignment via the aspf= (SPF alignment) and adkim= (DKIM alignment) tags:

Alignment Mode Tag Syntax Matching Rule (Header From vs Authenticated Domain)
Relaxed (Default) aspf=r; adkim=r; Allows subdomains. mail.company.com aligns with company.com (same Organizational Domain).
Strict aspf=s; adkim=s; Requires exact FQDN character match. mkt.company.com fails if Return-Path is company.com.

3. 4-Phase Progressive Adoption Timeline

Deploying a rejection policy (p=reject) immediately without prior reporting telemetry will result in widespread drop of legitimate business emails sent via unaligned SaaS vendors. Organizations should follow this 4-phase rollout plan:

Phase 1: Passive Monitoring (Weeks 1–4) p=none; pct=100

No mail delivery is altered. Receivers generate daily XML aggregate reports sent to the designated rua=mailto:[email protected] address.

v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1;
Phase 2: Gradual Quarantine (Weeks 5–6) p=quarantine; pct=25

Quarantine (Spam folder delivery) is applied to 25% of unaligned traffic. Validates that legitimate mailstreams pass without disruption.

v=DMARC1; p=quarantine; pct=25; rua=mailto:[email protected];
Phase 3: Full Quarantine (Week 7) p=quarantine; pct=100

100% of unaligned messages are routed to Spam folders. Verifies zero user helpdesk complaints.

Phase 4: Total Enforcement & Anti-Phishing (Final) p=reject; pct=100

Complete anti-spoofing protection. Any email lacking aligned SPF or valid DKIM signatures is rejected during the SMTP transaction (HTTP/SMTP 554 5.7.1 error code).

v=DMARC1; p=reject; aspf=r; adkim=r; rua=mailto:[email protected];

4. XML Aggregate Report Parsing (RUA Telemetry)

Mail receiver networks (Google, Microsoft, Yahoo, Comcast) issue daily compressed XML report archives. A representative RUA record entry exhibits the following structure:

<record>
<row>
<source_ip>198.51.100.45</source_ip>
<count>1420</count>
<policy_evaluated>
<disposition>none</disposition>
<spf>pass</spf>
<dkim>pass</dkim>
</policy_evaluated>
</row>
</record>

5. CLI Verification & BIND 9 / Cloudflare Record Syntax

To verify the existence of a DMARC policy record for a target domain using the command-line utility dig:

$ dig +short TXT _dmarc.your-domain.com
"v=DMARC1; p=reject; rua=mailto:[email protected];"
Audit Real-Time DMARC Record
Analyze policy enforcement, alignment parameters, and RUA telemetry endpoints for any domain.