Browse Definitions :
Definition

Domain-based Message Authentication, Reporting and Conformance (DMARC)

Domain-based Message Authentication, Reporting and Conformance (DMARC) is an email authentication and reporting protocol designed to help ensure the authenticity of the sender’s identity.

DMARC protects email from spoofing, phishing and spamming. The protocol helps make certain that the listed sender is who they are supposed to be, making email users more secure and protecting brands against abuse of their images.

DMARC builds on the commonly-deployed Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) protocols. DMARC adds linkage to the author’s domain name with the :From: header and standardized policies for recipient handling of authentication failures. Receivers-to-sender reporting is improved for anti-spam purposes.

A policy for DMARC allows a sender domain to specify if its email’s use of SPF and/or DKIM. Policies can be set for sending email to a spam folder or reject it if the authentication methods fail. If an email recipient gets an email that fails these authentications, they also have an option to report it back to the sending domain.

DMARC only protects against direct domain spoofing. Users can still be fooled by similar domains that trick them by appearing close enough, e.g. domainname.com vs domaimename.com. The protocol also fails to protect against situations where the sender is faked as the same name as the recipient. Despite limitations, DMARC’s additional protections were welcomed. Within a year of its debut in 2012, DMARC was deployed on 60 percent of email inboxes.

This was last updated in November 2017

Continue Reading About Domain-based Message Authentication, Reporting and Conformance (DMARC)

SearchCompliance
  • OPSEC (operations security)

    OPSEC (operations security) is a security and risk management process and strategy that classifies information, then determines ...

  • smart contract

    A smart contract is a decentralized application that executes business logic in response to events.

  • compliance risk

    Compliance risk is an organization's potential exposure to legal penalties, financial forfeiture and material loss, resulting ...

SearchSecurity
  • Secure Shell (SSH)

    SSH, also known as Secure Shell or Secure Socket Shell, is a network protocol that gives users, particularly system ...

  • NIST Cybersecurity Framework

    The NIST Cybersecurity Framework (NIST CSF) is a policy framework surrounding IT infrastructure security.

  • Advanced Encryption Standard (AES)

    The Advanced Encryption Standard (AES) is a symmetric block cipher chosen by the U.S. government to protect classified ...

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • change control

    Change control is a systematic approach to managing all changes made to a product or system.

  • disaster recovery (DR)

    Disaster recovery (DR) is an organization's ability to respond to and recover from an event that affects business operations.

SearchStorage
  • secondary storage

    Secondary storage is persistent storage for noncritical data that doesn't need to be accessed as frequently as data in primary ...

  • optical storage

    Optical storage is any storage type in which data is written and read with a laser.

  • JBOD (just a bunch of disks)

    JBOD, which stands for 'just a bunch of disks,' is a type of multilevel configuration for disks.

Close