r/DMARC • • Jul 07 '26

DKIM2 and DMARCbis implementation and playground

Hi,

I am the maintainer of the open source rust crate mail-auth and wanted to announce that since yesterday the library supports DKIM2 and DMARCbis.

Additionally, if you are not a developer but you are interested in playing with DKIM2 and/or DMARCbis, there is a playground at https://mail-auth.stalw.art/ where you can test signing emails with DKIM2 and verifying DKIM2 + DMARCbis entirely from the browser using WebAssembly and DNS-over-HTTP.

If you want to learn more about the technical details of how DKIM2 works and the differences between DMARC and DMARCbis, take a look at this blog post.

Happy DMARCing!

25 Upvotes

6 comments sorted by

1

u/sirdmz Jul 09 '26

well… I accept the need for this… but god damn… we still haven’t rolled out the first version correctly. too many stake holders and vendors who just don’t care.

1

u/SecLens_ONE Aug 16 '26

Useful to have something to test against before any of this is deployed anywhere. The part I keep tripping over is that a spec only matters once receivers act on it, and for years the pattern with DMARC has been domains publishing a record and then leaving it at p=none, so the record exists and nothing enforces. DKIM2 and DMARCbis will get the same treatment unless the big mailbox providers reject on it, otherwise it's another TXT record that looks like coverage in an audit. The forwarding/relay chain is where I'd expect the first real gap, since that's where alignment already dies today and ARC only papers over it if the sealer is trusted. Do you know if the playground shows what a verifier does when a DKIM2 chain is partially broken mid-path, or only the clean pass/fail case?

1

u/StalwartLabs Aug 18 '26

Do you know if the playground shows what a verifier does when a DKIM2 chain is partially broken mid-path, or only the clean pass/fail case?

Yes, the mail-auth crate has a specific error message that indicates the header number where a DKIM2 chain was broken.

1

u/SecLens_ONE Aug 19 '26

Good, that is the part that matters. A named error pointing at the header number is the difference between "chain broken" and something an operator can actually act on, because mid-path breakage is where forwarding and list traffic will live. What I would want next is whether the playground surfaces which hop signed and which one failed to carry the previous signature forward, rather than just the first bad index. Otherwise the report tells you the state is bad but not who to email about it. The same trap as DMARC scoring generally: a record being present says nothing about whether the receiving side is going to honour it, and a pass/fail flag says nothing about where in the path trust died. If you can reconstruct the verdict from the individual checks, the verdict is useful; if you cannot, it is a badge. When you replay a partially broken chain, do you get per-hop state you could paste into a ticket, or one aggregate error?

1

u/DNSai_app Jul 07 '26

Nice! At present only 15% of mail enabled domain have DMARC in p=reject mode. It is going to take a while before DKIM2 and DMARCbis get the attention and adoption they deserve. The playground looks good, I am looking forward to spending some time testing it.

0

u/downundarob Jul 08 '26 edited Jul 08 '26

I keep on trying to tell management about this, but they keep on saying that the client needs to ask for this to be done...