• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 390969-180 | Support: +49 5251 390969-300
NoSpamProxy
  • PRODUCTS
    • Platforms
      • NoSpamProxy Cloud
      • NoSpamProxy Server
      • NoSpamProxy 25Reports
  • SOLUTIONS
    • Threat Protection
      • Protection against Spam, Phishing & Malware
      • AI Threat Detection
      • Isolated File Analysis
      • Microsoft 365 Mail Security
    • Secure Email Communication
      • Email Encryption
      • Automatic Certificate Management
      • Search for Public Keys
    • Productivity & Compliance
      • Sending Large Files
      • Email Disclaimer
  • INDUSTRIES
    • By Company Size
      • Large Companies
      • Small and Medium-Sized Enterprises
    • Regulated Industries
      • Public Institutions
      • Healthcare
      • Finance
      • Law
    • Success Stories
      • Testimonials
      • Awards
  • PARTNERS
    • Resellers
      • Finding Resellers
      • Become a Reseller
      • Become an MSP Partner
    • For Existing Partners
      • Partner Portal
      • Partner Trainings
      • NFR Licenses
  • RESOURCES
    • Support
      • Online Documentation
      • Forum
      • Support
    • Continuing Education
      • Training Courses
      • Webcasts
    • Knowledge
      • Blog
      • Newsletter
    • Downloads
      • NoSpamProxy Server
    • Events
      • Events
      • Webcasts
  • PRICING
  • CONTACT
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • DMARCbis: Die nächste Evolutionsstufe der E-Mail-Authentifizierung

DMARCbis: The next evolutionary step in email authentication

Stefan Cink | Director Business and Professional Services
Author: Stefan CinkDirector Business and Professional Serviceshttps://www.linkedin.com/in/stefan-cink/–Connect on LinkedIn

Since the introduction of DMARC (Domain-based Message Authentication, Reporting and Conformance) in 2015, the protocol has established itself as an integral part of email security. However, with the increasing complexity of email infrastructures and ever new requirements for interoperability and clarity, it was time for an update. This update is called DMARCbis and brings with it some significant changes.

24.07.2025|zuletzt aktualisiert:11.08.2025

What is DMARCbis?

DMARCbis is a revised version of the original DMARC standard and is currently listed as a draft at the IETF (Internet Engineering Taskforce). The new version aims to improve and modernize the original DMARC standard from 2015 (RFC 7489).

Why DMARCbis?

DMARCbis is not intended as a radical reinvention, but as an evolutionary development. The aim is to make the specification clearer, more robust and easier to implement. While existing DMARC entries remain valid, organizations benefit from adapting to the new standards through

  • improved interoperability,

  • clearer guidelines, and

  • enhanced security mechanisms.

What’s new in DMARCbis?

1. DNS Treewalk instead of Public Suffix List (PSL)

The most significant change concerns the definition of the so-called Organizational Domain (OrgDomain). This is an essential component of DMARC. On the one hand, it serves as a fallback if no DMARC record can be found under the domain specified in the header From. On the other hand, the role of the OrgDomain as a reference domain is more clearly defined, especially for comparison when ‘relaxed’ or ‘strict’ mode is enabled.

Previously, the Public Suffix List (PSL) – an externally maintained list of domain extensions such as .com, .de, .co.uk or .gov – was used to determine the OrgDomain. When using subdomains such as news.mail.example.com, this procedure requires that either a DMARC entry is stored for each individual subdomain that is used for sending emails, or that the DMARC entry of the OrgDomain is valid for all subdomains, regardless of the level. This procedure leaves little room for flexibility.

DMARCbis replaces this with a DNS-based treewalk procedure:

The treewalk starts with the full domain name specified in the header-from (e.g. _dmarc.news.mail.example.com) and works its way up the hierarchy step by step until a valid DMARC entry is found. However, there is a maximum hierarchy depth of 8 levels. So if the domain specified in the Header-From has more than 8 levels – such as a.b.c.d.e.f.g.h.i.j.mail.example.com – the treewalk starts searching at _dmarc.g.h.i.j.mail.example.com if no DMARC entry was found under _dmarc.a.b.c.d.e.f.g.h.i.j.mail.example.com.

New tags such as psd=y or psd=n help to explicitly define domain boundaries. This procedure is DNS-native, more robust and reduces the external dependency on the PSL.

A valid DMARC record with psd=n indicates that this is the organization domain and the selection process is complete. A valid DMARC record with psd=y, which is not for the domain where the treewalk begins, indicates that the organization domain is the domain one level below it in the DNS hierarchy and the selection process is complete.

2. Simplification of the tags

DMARCbis does away with some legacy issues.

Here are some examples:

Obsolete tagsNew/alternative tagsPurpose
pctt (test mode)Percentage application omitted in favor of clear test signals
rf, rin/aSimplification of reporting mechanisms
–npPolicy for non-existent subdomains
–psdMarking of public suffix domains
Obsolete tagsNew/alternative tagsPurpose
pctt ( test mode)Percentage application omitted in favor of clear test signals
rf, rin/aSimplification of reporting mechanisms
–npPolicy for non-existent subdomains
–psdMarking of public suffix domains

3. A clearer specification

The entire specification has been restructured, with better examples and a new section on “Full DMARC Participation”, which describes what full participation in DMARC means – for both domain owners and receiving mail servers.

What does this mean for companies?

  • Existing DMARC entries remain valid.
  • It is recommended to check the configuration and adapt it to the new tags and procedures if necessary.
  • Operators of subdomains or public suffix domains in particular benefit from the new control options.

Conclusion: evolution instead of revolution

DMARCbis does not bring any disruptive changes, but important improvements in terms of clarity, security and future viability. The new treewalk procedure is a milestone in DNS-based authentication and makes DMARC more robust against abuse through subdomain spoofing.

Further articles on sender reputation and email security

Part 1: Authenticated Received Chain (ARC)

Part 2: Sender Policy Framework (SPF)

Part 3: DomainKeys Identified Mail (DKIM)

Part 4: Domain-based Message Authentication, Reporting and Conformance (DMARC)

Part 5: DNS-based Authentication of Named Entities (DANE)

Part 6: DMARCbis

Not yet using NoSpamProxy?

With NoSpamProxy you can reliably protect your company from spoofing attacks and benefit from many other security functions. Request your free trial version now!

Get your free NoSpamProxy trial now!
  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

NoSpamProxy Newsletter

Subscribe to Newsletter

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • News
  • Product
  • Product
  • Tech & Support
  • Tech & Support
  • Events
  • Events
Net at Work GmbH
Am Hoppenhof 32 A
33104 Paderborn
Tel. +49 5251 390969-000
Fax +49 5251 390969-009
www.nospamproxy.com
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • About us
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Finding resellers
  • Becoming a reseller
  • Becoming a MSP Partner
  • Newsletter Subscription
  • Order Certificates

Categories

  • All topics
  • News
  • Support
  • Product
  • Events
  • Updates

Latest News

  • NoSpamProxy Info Icon
    NoSpamProxy continues to evolve: greater focus on product and partner business01.09.2026 - 10:00
  • Info Icon
    Action Required: Renew Permissions for the Entra ID User Import14.08.2026 - 13:59
  • info icon
    NoSpamProxy and TLS Certificates: What Will Change by 202907.08.2026 - 10:00
IMPRINT • EULA • Privacy Policy • • © 2026 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to Instagram
Link to: Why you should activate ARC in NoSpamProxy now Link to: Why you should activate ARC in NoSpamProxy now Why you should activate ARC in NoSpamProxy nowWarum Sie ARC in NoSpamProxy jetzt aktivieren sollten Preview Link to: Time-of-Click Protection – with the URL Safeguard in NoSpamProxy Link to: Time-of-Click Protection – with the URL Safeguard in NoSpamProxy Time-of-Click Protection – mit dem URL Safeguard von NoSpamProxy PreviewTime-of-Click Protection – with the URL Safeguard in NoSpamProxy
Scroll to top Scroll to top Scroll to top