Sendmarc is already preparing for these changes, so you can adopt the updated standard seamlessly.
Page contents
DMARCbis is the most significant update to Domain-based Message Authentication, Reporting, and Conformance (DMARC) since the protocol was first introduced. The “bis” suffix is part of the Internet Engineering Task Force’s (IETF) naming convention and signals a revision of an existing standard.
Unlike the original DMARC specification (RFC 7489), which was published as an Informational document in 2015, DMARCbis is set to be released as a Proposed Standard. This advancement formalizes DMARC’s place as a proven and widely adopted email authentication protocol, while reinforcing its global role in safeguarding email and highlighting the growing recognition of its importance across industries.
Often referred to as “DMARC 2.0,” this update builds on more than a decade of global deployment and operational lessons.
It enhances the original RFC by:
Importantly, DMARCbis maintains backward compatibility. It continues to use v=DMARC1 as the version, meaning businesses with active records don’t need to make immediate changes. Instead, they can adopt the new features at their own pace to strengthen protection against domain spoofing and unauthorized email use.
While DMARCbis doesn’t require businesses to make immediate changes, leveraging a dedicated platform ensures your records, reporting, and policies stay compliant as standards evolve.
DMARCbis introduces several important updates designed to make email authentication more reliable, easier to implement, and better suited for today’s threat environment. Below are the most significant changes security professionals and domain owners should be aware of.
The updated document is now split into three separate drafts:
This separation makes the protocol easier to understand, implement, and maintain over time.
DMARCbis introduces clearer rules for what businesses and receivers must do to fully support the standard. By setting clear expectations, the update improves interoperability and strengthens global adoption.
One of the most significant updates DMARC 2.0 includes is the replacement of the Public Suffix List (PSL) with a DNS Tree Walk algorithm. The algorithm queries successive levels of the domain hierarchy, moving up one label at a time, until it finds a record with psd=y (public suffix domain) or psd=n (organizational boundary).
Important technical details:
psd valueThis DNS-native approach:
Transition consideration: During the transition period, some implementations may still use the PSL while others use Tree Walk, potentially leading to different domain determinations. Companies should consider using strict alignment and publishing explicit DMARC records for all domains to avoid interoperability issues.
Managing this manually can be complex, but a purpose-built platform like Sendmarc can simplify the process.
psd, np, t)DMARCbis introduces new policy tags to give businesses finer control. These are:
psd: Explicitly marks public suffix domainsy indicates the domain is a public suffix domainn indicates the domain is the organizational domainu is the default, letting Tree Walk determine the organizational domainnp: Defines policies for non-existent subdomains, preventing spoofing attacks using fake names like ceo.example.comt: Replaces the legacy pct tag with a clearer “testing mode” signaly indicates testing mode (policy shouldn’t be enforced)n is the default (apply the published policy)pct, rf, ri)A few legacy tags have been deprecated because they caused inconsistency:
pct (percentage)rf (report format)ri (report interval)The new t tag provides a simpler testing signal, while reporting formats and intervals are now standardized.
Aggregate and failure reporting are now defined in dedicated drafts, with aggregate reporting adopting stricter requirements to improve consistency and security. Updates include:
DMARCbis introduces important guidance regarding mailing lists and email forwarding. The specification now discourages using a p=reject policy when there’s a possibility that mailing lists are involved in your company’s email flows. This is because mailing lists often break both SPF and DKIM alignment, potentially causing legitimate emails to be rejected and automatically unsubscribing users from mailing lists.
Businesses should carefully consider their email ecosystem before implementing strict rejection policies. That said, Sendmarc strongly encourages domain owners to work toward a p=reject policy wherever possible, because it’s the only way to guarantee full protection against unauthorized use of your domain.
DMARCbis has a complex publication status that domain owners should understand. The main DMARCbis document (draft-ietf-dmarc-dmarcbis-41) and aggregate reporting document (draft-ietf-dmarc-aggregate-reporting-32) were approved by the Internet Engineering Steering Group (IESG) in 2025.
But the previous DMARC Working Group (WG) dissolved, leaving behind an incomplete failure reporting document (draft-ietf-dmarc-failure-reporting-13) that creates a reference issue.
Current status: A new DMARC Working Group has been chartered specifically to resolve the failure reporting document issue. This working group must either:
or
The base document was last updated on April 4, 2025 (draft version 41). While industry experts initially expected publication sometime in 2025, the current complications with the document cluster mean the timeline is uncertain until the failure reporting issue is resolved.
DMARCbis represents the next stage in email authentication, enhancing clarity, security, and operational flexibility. It builds on more than a decade of experience with DMARC to introduce practical improvements that make policies easier to manage and enhance effectiveness against modern phishing and spoofing threats.
Key benefits include:
At Sendmarc, we plan to align our platform with DMARCbis as soon as the standard is finalized, ensuring customers can seamlessly adopt the new features. This means you’ll be able to take advantage of the protocol’s enhancements without additional complexity.
Book a demo with Sendmarc to see how we can help you prepare for “DMARC 2.0” and secure your email environment for the future.
DMARCbis is the updated version of Domain-based Message Authentication, Reporting, and Conformance (DMARC). Also called “DMARC 2.0,” it introduces technical improvements such as the DNS Tree Walk algorithm, new policy tags, and enhanced reporting while maintaining backward compatibility with existing DMARC records.
No, you don’t need to change your current DMARC record for DMARCbis. The update continues to use the same version identifier, v=DMARC1. Your existing records remain valid, but you can adopt the new features over time to strengthen email authentication and security.
The DNS Tree Walk improves authentication in DMARCbis by replacing the reliance on the Public Suffix List (PSL). Instead, it queries the DNS directly, moving through domain levels until it identifies the correct organizational boundary.