What is DMARCbis?
DMARCbis is the most significant update to DMARC (Domain-based Message Authentication, Reporting, and Conformance) since the protocol was first introduced. The “bis” suffix is part of the Internet Engineering Task Force’s (IETF) naming convention and signals a revision of an existing standard.
Want a clear view of what DMARCbis means in practice? Watch our fireside chat with co-editor Todd Herr:
Unlike the original DMARC specification (RFC 7489), which was published as an Informational document in 2015, DMARCbis has been released as a Proposed Standard. This advancement formalizes DMARC’s place as a proven and widely adopted email authentication protocol, while reinforcing its global role in safeguarding email and highlighting the growing recognition of its importance across industries.
This update builds on more than a decade of global deployment and operational lessons.
It enhances the original RFC by:
- Providing a clearer specification structure with more examples
- Improving domain boundary determination with DNS-native mechanisms
- Simplifying tags by removing legacies
- Increasing reporting requirements to strengthen visibility and security
Importantly, DMARCbis maintains backward compatibility. It continues to use v=DMARC1 as the version, meaning businesses with active records don’t need to make immediate changes. Instead, they can adopt the new features at their own pace to strengthen protection against domain spoofing and unauthorized email use.
While DMARCbis doesn’t require businesses to make immediate changes, leveraging a dedicated platform ensures your records, reporting, and policies stay compliant as standards evolve.
What is changing in DMARCbis: Key updates
DMARCbis introduces several important updates designed to make email authentication more reliable, easier to implement, and better suited for today’s threat environment. Below are the most significant changes security professionals and domain owners should be aware of.
Improved specification structure
The updated document is now split into three separate drafts:
- Core protocol: Defines DMARC
- Aggregate reporting: Outlines how daily reports are generated and formatted
- Forensic reporting: Details how forensic reports provide information on authentication failures
This separation makes the protocol easier to understand, implement, and maintain over time.
Conformance requirements for full participation
DMARCbis introduces clearer rules for what businesses and receivers must do to fully support the standard. By setting clear expectations, the update improves interoperability and strengthens global adoption.
DNS Tree Walk algorithm
One of the most significant updates DMARCbis includes is the replacement of the Public Suffix List (PSL) with a DNS Tree Walk algorithm. The algorithm queries successive levels of the domain hierarchy, moving up one label at a time, until it finds a record with psd=y (public suffix domain) or psd=n (organizational boundary).
Important technical details:
- The walk is limited to a maximum of eight levels to prevent excessive DNS queries
- If a domain has eight or more labels, it removes the leftmost labels until only seven remain before starting the walk
- The walk stops when it finds a valid DMARC record with an explicit
psdvalue
This DNS-native approach:
- Eliminates reliance on third-party lists
- Enhances the likelihood of uniform updates
- Improves the accuracy and reliability of boundary detection
Transition consideration: During the transition period, some implementations may still use the PSL while others use Tree Walk, potentially leading to different domain determinations. Companies should consider using strict alignment and publishing explicit DMARC records for all domains to avoid interoperability issues.
Managing this manually can be complex, but a purpose-built platform like Sendmarc can simplify the process.
New tags (psd, np, t)
DMARCbis introduces new policy tags to give businesses finer control. These are:
psd: Explicitly marks public suffix domainsyindicates the domain is a public suffix domainnindicates the domain is the organizational domainuis the default, letting Tree Walk determine the organizational domain
np: Defines policies for non-existent subdomains, preventing spoofing attacks using fake names like ceo.example.comt: Replaces the legacypcttag with a clearer “testing mode” signalyindicates testing mode (policy shouldn’t be enforced)nis the default (apply the published policy)
Removed tags (pct, rf, ri)
A few legacy tags have been deprecated because they caused inconsistency:
pct(percentage)rf(report format)ri(report interval)
The new t tag provides a simpler testing signal, while reporting formats and intervals are now standardized.
Enhanced reporting
Aggregate and forensic reporting are now defined in dedicated drafts, with aggregate reporting adopting stricter requirements to improve consistency and security. Updates include:
- Mandatory external URI validation for reports sent outside the domain
- Standardized formatting and filenames for attachments
- Stricter enforcement of XML and gzip
Important guidance on mailing lists
DMARCbis introduces important guidance regarding mailing lists and email forwarding. The specification now discourages using a p=reject policy when there’s a possibility that mailing lists are involved in your company’s email flows. This is because mailing lists often break both SPF and DKIM alignment, potentially causing legitimate emails to be rejected and automatically unsubscribing users from mailing lists.
Businesses should carefully consider their email ecosystem before implementing strict rejection policies. That said, Sendmarc strongly encourages domain owners to work toward a p=reject policy wherever possible, because it’s the only way to guarantee full protection against unauthorized use of your domain.
Secure your domain for the future
DMARCbis represents the next stage in email authentication, enhancing clarity, security, and operational flexibility. It builds on more than a decade of experience with DMARC to introduce practical improvements that make policies easier to manage and enhance effectiveness against modern phishing and spoofing threats.
Key benefits include:
- More accurate organizational domain detection through the DNS Tree Walk algorithm
- Simplified tag management with clearer testing signals
- Improved aggregate reporting for better visibility
- Stronger safeguards against spoofing on non-existent subdomains
- Better support for complex domain structures and public suffix domains
- Enhanced interoperability through stricter conformance requirements
The Sendmarc Platform aligns with DMARCbis, giving customers a straightforward path to the updated standard.
Book a demo with Sendmarc to see how we can help you prepare for DMARCbis and secure your email environment for the future.