• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 304-800 | Support: +49 5251 304-636
NoSpamProxy
  • PRODUCT
    • NoSpamProxy Cloud
    • NoSpamProxy Protection
    • NoSpamProxy Encryption
    • NoSpamProxy Large Files
    • NoSpamProxy Disclaimer
    • NoSpamProxy 25Reports
  • SOLUTIONS
    • M365 Mail Security
    • Managed Certificates
    • 32Guards
  • RESOURCES
    • Documentation
    • Forum
    • Webcast Training
    • Training Courses
    • Support
    • Software Download
  • PARTNERS
    • Finding Resellers
    • Becoming Reseller
    • Partner Portal
    • NFR Licenses
  • COMPANY
    • Contact
    • Testimonials
    • Team
    • Career
    • Events
    • Awards
  • PRICES
  • BLOG
    • Blog
    • Newsletter Subscription
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • DMARCbis: Die nächste Evolutionsstufe der E-Mail-Authentifizierung

DMARCbis: The next evolutionary step in email authentication

Stefan Cink | Director Business and Professional Services
Author: Stefan CinkDirector Business and Professional Serviceshttps://www.linkedin.com/in/stefan-cink/–Connect on LinkedIn

Since the introduction of DMARC (Domain-based Message Authentication, Reporting and Conformance) in 2015, the protocol has established itself as an integral part of email security. However, with the increasing complexity of email infrastructures and ever new requirements for interoperability and clarity, it was time for an update. This update is called DMARCbis and brings with it some significant changes.

24.07.2025|zuletzt aktualisiert:11.08.2025

What is DMARCbis?

DMARCbis is a revised version of the original DMARC standard and is currently listed as a draft at the IETF (Internet Engineering Taskforce). The new version aims to improve and modernize the original DMARC standard from 2015 (RFC 7489).

Why DMARCbis?

DMARCbis is not intended as a radical reinvention, but as an evolutionary development. The aim is to make the specification clearer, more robust and easier to implement. While existing DMARC entries remain valid, organizations benefit from adapting to the new standards through

  • improved interoperability,

  • clearer guidelines, and

  • enhanced security mechanisms.

What’s new in DMARCbis?

1. DNS Treewalk instead of Public Suffix List (PSL)

The most significant change concerns the definition of the so-called Organizational Domain (OrgDomain). This is an essential component of DMARC. On the one hand, it serves as a fallback if no DMARC record can be found under the domain specified in the header From. On the other hand, the role of the OrgDomain as a reference domain is more clearly defined, especially for comparison when ‘relaxed’ or ‘strict’ mode is enabled.

Previously, the Public Suffix List (PSL) – an externally maintained list of domain extensions such as .com, .de, .co.uk or .gov – was used to determine the OrgDomain. When using subdomains such as news.mail.example.com, this procedure requires that either a DMARC entry is stored for each individual subdomain that is used for sending emails, or that the DMARC entry of the OrgDomain is valid for all subdomains, regardless of the level. This procedure leaves little room for flexibility.

DMARCbis replaces this with a DNS-based treewalk procedure:

The treewalk starts with the full domain name specified in the header-from (e.g. _dmarc.news.mail.example.com) and works its way up the hierarchy step by step until a valid DMARC entry is found. However, there is a maximum hierarchy depth of 8 levels. So if the domain specified in the Header-From has more than 8 levels – such as a.b.c.d.e.f.g.h.i.j.mail.example.com – the treewalk starts searching at _dmarc.g.h.i.j.mail.example.com if no DMARC entry was found under _dmarc.a.b.c.d.e.f.g.h.i.j.mail.example.com.

New tags such as psd=y or psd=n help to explicitly define domain boundaries. This procedure is DNS-native, more robust and reduces the external dependency on the PSL.

A valid DMARC record with psd=n indicates that this is the organization domain and the selection process is complete. A valid DMARC record with psd=y, which is not for the domain where the treewalk begins, indicates that the organization domain is the domain one level below it in the DNS hierarchy and the selection process is complete.

2. Simplification of the tags

DMARCbis does away with some legacy issues.

Here are some examples:

Obsolete tagsNew/alternative tagsPurpose
pctt (test mode)Percentage application omitted in favor of clear test signals
rf, rin/aSimplification of reporting mechanisms
–npPolicy for non-existent subdomains
–psdMarking of public suffix domains
Obsolete tagsNew/alternative tagsPurpose
pctt ( test mode)Percentage application omitted in favor of clear test signals
rf, rin/aSimplification of reporting mechanisms
–npPolicy for non-existent subdomains
–psdMarking of public suffix domains

3. A clearer specification

The entire specification has been restructured, with better examples and a new section on “Full DMARC Participation”, which describes what full participation in DMARC means – for both domain owners and receiving mail servers.

What does this mean for companies?

  • Existing DMARC entries remain valid.
  • It is recommended to check the configuration and adapt it to the new tags and procedures if necessary.
  • Operators of subdomains or public suffix domains in particular benefit from the new control options.

Conclusion: evolution instead of revolution

DMARCbis does not bring any disruptive changes, but important improvements in terms of clarity, security and future viability. The new treewalk procedure is a milestone in DNS-based authentication and makes DMARC more robust against abuse through subdomain spoofing.

Further articles on sender reputation and email security

Part 1: Authenticated Received Chain (ARC)

Part 2: Sender Policy Framework (SPF)

Part 3: DomainKeys Identified Mail (DKIM)

Part 4: Domain-based Message Authentication, Reporting and Conformance (DMARC)

Part 5: DNS-based Authentication of Named Entities (DANE)

Part 6: DMARCbis

Not yet using NoSpamProxy?

With NoSpamProxy you can reliably protect your company from spoofing attacks and benefit from many other security functions. Request your free trial version now!

Get your free NoSpamProxy trial now!
  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • Product
  • Tech & Support
  • Events

NoSpamProxy Newsletter

Subscribe to Newsletter
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • NoSpamProxy Cloud
  • NoSpamProxy Encryption
  • NoSpamProxy Large Files
  • NoSpamProxy Disclaimer
  • Price request
  • Team
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Becoming a reseller
  • Partners
  • Order Certificates
  • Newsletter

Categories

  • All topics
  • News
  • Support
  • Updates
  • Order certificates

Latest News

  • Gelöschter SPF-Eintrag: Warum DNS-Alarmierung unverzichtbar ist 800x800
    When the service provider deletes the SPF record: Why DNS alerts are essential16.01.2026 - 10:00
  • Link Wrapping als Angriffsvektor 800x800
    Link wrapping as an attack vector05.01.2026 - 10:02
  • Info Icon
    React vulnerability: NoSpamProxy is not affected12.12.2025 - 13:00
IMPRINT • EULA • Privacy Policy • • © 2026 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
Link to: Why you should activate ARC in NoSpamProxy now Link to: Why you should activate ARC in NoSpamProxy now Why you should activate ARC in NoSpamProxy nowWarum Sie ARC in NoSpamProxy jetzt aktivieren sollten Preview Link to: it-sa 2025 – Get your free ticket now! Link to: it-sa 2025 – Get your free ticket now! it-sa 2022 Previewit-sa 2025 – Get your free ticket now!
Scroll to top Scroll to top Scroll to top