RFC 7489 — DMARC (superseded)

Domain-based Message Authentication, Reporting, and Conformance (DMARC)

Obsolete. Superseded by RFC 9989, RFC 9990, RFC 9991.
Status
Informational
Published
2015

RFC 7489 is obsolete. It defined DMARC from 2015 until 2026, and almost every DMARC article, vendor page and Stack Overflow answer still cites it.

It was replaced by three documents:

Instead of RFC 7489, citeFor
RFC 9989The protocol — policy, alignment, record syntax
RFC 9990Aggregate report format
RFC 9991Failure report format

It was never a standard

RFC 7489 was Informational, not Standards Track. DMARC was deployed at internet scale for a decade on a document that formally described what some people had agreed to do rather than specifying what implementers must do.

That is not a criticism of it — publishing as Informational was how DMARC got adopted quickly — but it explains a decade of interoperability friction. Where the document left latitude, implementations diverged, and receivers could disagree about which policy applied to a subdomain or how to treat a pct value of 37. RFC 9989 is Proposed Standard and closes most of those gaps.

Is your record out of date?

Probably not. The record syntax barely changed, and a record published against RFC 7489 is very likely a valid RFC 9989 record already.

The exceptions are the three tags now marked historic: pct, rf and ri. If your record carries any of them, see what changed in RFC 9989pct in particular has a direct replacement in the new t= tag.

Why this page exists

Mostly so that a search for “DMARC RFC 7489” lands somewhere that says this is the old one and points at the right document. Given how much material cites 7489, that will be true for years.

Read it: rfc-editor.org/rfc/rfc7489