« All posts

Why DMARC's new "NP" tag can fail with DNSSEC

The new np tag in DMARC conflicts with DNSSEC, impacting email security across domains.

The updated DMARC specification, RFC 9989, introduces the np tag to define policies for non-existent subdomains. However, this definition conflicts with RFC 9824, leading to issues with the np tag's functionality. This incompatibility affects all domains using DNSSEC, particularly with major DNS providers. Understanding this issue is crucial for engineers focusing on email security and domain management.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work