1. DMARC Architecture & The Concept of Domain Alignment
DMARC (Domain-based Message Authentication, Reporting, and Conformance), standardized in IETF RFC 7489, unifies SPF validation (RFC 7208) and DKIM cryptographic signatures (RFC 6376) under a single enterprise security policy.
DMARC addresses the historical vulnerability in the SMTP protocol where the visible RFC 5322 From: header displayed to end users was decoupled from the authenticated transport identity (Return-Path or DKIM signing domain). To satisfy a DMARC policy check, a message must achieve Domain Alignment across at least one underlying authentication mechanism.
2. Relaxed vs. Strict Domain Alignment Modes
RFC 7489 allows domain owners to configure the strictness of alignment via the aspf= (SPF alignment) and adkim= (DKIM alignment) tags:
| Alignment Mode | Tag Syntax | Matching Rule (Header From vs Authenticated Domain) |
|---|---|---|
| Relaxed (Default) | aspf=r; adkim=r; | Allows subdomains. mail.company.com aligns with company.com (same Organizational Domain). |
| Strict | aspf=s; adkim=s; | Requires exact FQDN character match. mkt.company.com fails if Return-Path is company.com. |
3. 4-Phase Progressive Adoption Timeline
Deploying a rejection policy (p=reject) immediately without prior reporting telemetry will result in widespread drop of legitimate business emails sent via unaligned SaaS vendors. Organizations should follow this 4-phase rollout plan:
No mail delivery is altered. Receivers generate daily XML aggregate reports sent to the designated rua=mailto:[email protected] address.
Quarantine (Spam folder delivery) is applied to 25% of unaligned traffic. Validates that legitimate mailstreams pass without disruption.
100% of unaligned messages are routed to Spam folders. Verifies zero user helpdesk complaints.
Complete anti-spoofing protection. Any email lacking aligned SPF or valid DKIM signatures is rejected during the SMTP transaction (HTTP/SMTP 554 5.7.1 error code).
4. XML Aggregate Report Parsing (RUA Telemetry)
Mail receiver networks (Google, Microsoft, Yahoo, Comcast) issue daily compressed XML report archives. A representative RUA record entry exhibits the following structure:
5. CLI Verification & BIND 9 / Cloudflare Record Syntax
To verify the existence of a DMARC policy record for a target domain using the command-line utility dig: