Closed toddherr closed 6 months ago
Added the following text to the end of Interoperability Considerations in rev -31:
As a final note, one possible mitigation to the problems caused by Domain Owners publishing p=reject when they should not or Mail Receivers rejecting messages solely on the basis of a p=reject policy is the Autheticated Received Chain (ARC) protocol described in [@RFC8617]. However, as of this writing, use of ARC is nascent, as is industry experience with it in connection with DMARC.
Should ARC be mentioned in DMARCbis when speaking of indirect mail flows?
For example:
"One possible mitigation to problem X is [ARC], which provides for a mechanism to demonstrate 'chain-of-custody' of a message. However, use of ARC is nascent, as is industry experience with it in connection with DMARC."