Skip to main content
// RFC 7489 ANTI-SPOOFING RADAR • GOOGLE & YAHOO MANDATE AUDIT

RFC 7489 DMARC Policy Validator

PASSIVE DOH RECON

Instant RFC 7489 DMARC policy inspector. Evaluates policy enforcement levels (`p=none`, `quarantine`, `reject`), organizational domain tree-walking fallbacks, SPF/DKIM alignment rules, and RFC 7489 § 7.1 external destination authorization.

INITIALIZING DMARC ENGINE...

RFC 7489 Architecture & Delivery Standards

// REFERENCE SPEC
01 // TREE-WALKING & PSL

Organizational Domain Fallback

Per RFC 7489 Section 6.6.3, if a deep subdomain like app.staging.example.com has no direct DMARC record, receivers perform exactly one fallback query at the Organizational Domain (example.com) determined by the Public Suffix List (PSL).

02 // ANTI-SPOOFING BARRIER

The Danger of p=none

Over 60% of published DMARC records use p=none. While useful for initial telemetry, p=none instructs mail receivers to deliver fraudulent emails directly to user inboxes, leaving domain reputation exposed to impersonation.

03 // DESTINATION PRIVACY

RFC 7489 § 7.1 Verification

When sending reports to external endpoints (e.g. dmarc@thirdparty.com), the receiving domain must publish an authorization record at domain._report._dmarc.thirdparty.com. Without this, receivers will drop telemetry reports.