DKIM2 and DMARCbis Have Landed: Stalwart Speaks Them First

DKIM2 and DMARCbis Have Landed: Stalwart Speaks Them First

Email authentication has just taken its biggest leap forward with the arrival of DKIM2 and DMARCbis. I explain how these new standards fix decades of flaws like signature breakage on forwarding and message replay attacks. Stalwart is the first mail server to fully support these protocols, creating a verifiable chain of custody that finally secures the path from author to recipient.

A valid signature means this domain vouches for this content, but until now it said nothing about who the message was for, where it has been, or where it is going next.
  1. qurren

    Aw hell. How many things do I have to set up just so that I can send e-mails from my own domain?

    The effect of all this seems to be less "making e-mail secure" and more "making it so that only Google, Apple, and Microsoft can send e-mail successfully"

  2. braiamp

    Despite what everyone said, I'm excited specifically for DKIM2. As someone that had managed a mailing list, that one is probably the hardest thing to juggle around and DKIM2 layering seems to fix that issue neatly. I hope postfix has a guide proto.

  3. peanut-walrus

    Missed opportunity to get rid of SPF. What I want to my DMARC policy to say: if someone is sending you an email that claims to be from my domain and it's not signed by one of the keys I have published under my domain, you should reject it, regardless where it came from.

    And on the receiving side, the policy is similarly simple: if I receive any unsigned or unaligned email, I will reject it.

    Edit: to clarify, I want there to be an option where I specify my DMARC policy to explicitly tell well-configured receiving servers "ignore whatever I have configured as my SPF record, only look at the signatures". There will no doubt be a long tail of mail servers where I will still need an SPF record for them to accept my mail.

    Edit2: Another feature that I feel is lacking is ability to give dkim selectors a scope - e.g. this key is only valid for these particular From addresses.

  4. Animats

    Questions:

    - How much infrastructure has to be fixed before this works, and in what order?

    - Can you send mail from something that doesn't have a DNS entry? How does this affect the first hop from a desktop or mobile SMTP client?

    - If an spam email came via SendGrid, Constant Spammer, or MailChump, are you going to be able to tell from the header signatures?

    - If your headers are correct, are you guaranteed mail bounces for un-deliverable emails?

  5. bigbuppo

    Can someone distill this down to how it will be used by the big three email providers to make it impossible to use email except through them?

More from this day

2026-07-08