Global | Google Bulk Sender Requirements | Bulk senders (over 5,000 emails/day) must authenticate domains with TLS, DKIM, and SPF, and have a DMARC policy of at least p=none. | Read more | Put into effect from February 2024 |
Global | Yahoo Bulk Sender Requirements | Bulk senders (over 5,000 emails/day) must authenticate domains with TLS, DKIM, and SPF, and have a DMARC policy of at least p=none | Read more | Put into effect from February 2024 |
Global | PCI-DSS version 4 compliance requirements | PCI DSS v4.0 requires automated mechanisms to prevent phishing; best practices suggest using DMARC, SPF, and DKIM. | Read more | Will be put into effect from March 2025 |
EU countries | GDPR (General Data Protection Regulation) | Under GDPR, you are required to have Data Processing Agreements (DPAs) with every single cloud service provider that, on behalf of your entity, handles the European consumers’ data. | Read more | Introduced in May 2018 |
EU countries | DORA (Digital Operational Resilience Act) | By applying to 20 different types of financial entities and ICT third-party service providers, the Digital Operational Resilience Act (DORA) aims to harmonize the rules regarding the operational resilience of the financial sector (i.e. banks, insurance companies, investment firms, etc.). DMARC can be of significant importance for financial institutions, as it offers protection from email-based cyber attacks, indirectly helping ensure compliance with the DORA Act. | Read more | Put into effect from January 2023 |
Canada | Email Management Services Configuration Requirements | Government emails must be verified using SPF, DKIM, and DMARC. | Read more | Last modified in 2024 |
Denmark | Minimum technical requirements for government authorities | Government agencies must implement a DMARC policy of p=reject on all domains. | Read more | Put into effect from March 2023 |
New Zealand | New Zealand Information Security Manual version 3.6 | Change of DMARC and DKIM control compliance from SHOULD to MUST and DMARC policy setting from p="none" to p="reject". | Read more | Put into effect from September 2022 |
Ireland | Public Sector Cyber Security Baseline Standards | The Public Sector Cyber Security Baselines suggest using SPF, DKIM, DMARC, and TLS to enhance email security. However, this is only a suggestion and not a requirement. | Read more | Put into effect from November 2022 |
Netherlands | “Comply or Explain” standards | It is a requirement for government agencies to implement DMARC, along with DKIM, SPF, STARTTLS, and DANE. This is part of the “Comply or Explain” standards for email protection and authentication. | Read more | Put into effect from December 2023 |
Saudi Arabia | Guide to Essential Cybersecurity Controls (ECC) Implementation | Saudi Arabian organizations are recommended to use DKIM, SPF, and DMARC as advanced phishing protection techniques to filter out fraudulent messages. | Read more | ECC was published by the NCA in 2018 |
UK | Government Cybersecurity Policy Handbook Principle | In March 2024, the Government Cyber Security Policy replaced the Minimum Cyber Security Policy. This update moved MTA-STS and TLS-RPT from ‘recommended’ to ‘must do’ and added a reference to PTR records. | Read more | Published in August 2016 Last modified in March 2024 |
United States | Binding Operational Directive 18-01 | The binding Operational Directive 18-01 requires all federal agencies to use STARTTLS, SPF, DKIM, and a DMARC policy of p=reject | Read more | Published/Last modified in October 2017 |
United States | HIPAA (Health Insurance Portability and Accountability Act) | Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HIPAA Privacy Rule determines national standards for safeguarding certain sensitive health-related information. DMARC can be an essential tool in ensuring compliance with HIPAA regulations. | Read more | Put into effect from August 1996 |
Australia | Information Security Manual by the ASD (Australian Signals Directorate) | Recommends using SPF, DKIM, and DMARC to keep email-based threats at bay. | Read more | Last updated in June 2024 |