Update DMARC guidance for RFC 9989 - #578
Update DMARC guidance for RFC 9989#578powder_blower (samuelchenardlovesboards) wants to merge 2 commits into
Conversation
|
Learn Build status updates of commit fd2bbd8: ✅ Validation status: passed
For more details, please refer to the build report. |
|
powder_blower (@samuelchenardlovesboards) - Thank you for your contribution. Would you take a moment to sign the Contributor License Agreement (CLA)? After the CLA is signed, someone can review your pull request. Thanks! Can you review the proposed changes? IMPORTANT: When the changes are ready for publication, adding a #label:"aq-pr-triaged" |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 300874df-ee23-4ca6-84e2-6fb62c327d0d
|
Learn Build status updates of commit 8de8e26:
|
| File | Status | Preview URL | Details |
|---|---|---|---|
| defender/docfx.json | Details | ||
| defender-office-365/email-authentication-dmarc-configure.md | ✅Succeeded |
defender/docfx.json
- Line 49, Column 41: [Warning: ms-service-subservice-invalid - See documentation]
Invalid value for 'ms.service': 'threat-intelligence'.
For more details, please refer to the build report.
Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.
|
Refreshing the build |
|
powder_blower (@samuelchenardlovesboards) please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.
Contributor License AgreementContribution License AgreementThis Contribution License Agreement (“Agreement”) is agreed to by the party signing below (“You”),
|
|
powder_blower (@samuelchenardlovesboards) Would you take a moment to sign the Contributor License Agreement (CLA)? After the CLA is signed, someone can review your pull request. Thanks! #label:"aq-pr-triaged" |
|
Learn Build status updates of commit 8de8e26:
|
| File | Status | Preview URL | Details |
|---|---|---|---|
| defender/docfx.json | Details | ||
| defender-office-365/email-authentication-dmarc-configure.md | ✅Succeeded |
defender/docfx.json
- Line 49, Column 41: [Warning: ms-service-subservice-invalid - See documentation]
Invalid value for 'ms.service': 'threat-intelligence'.
For more details, please refer to the build report.
Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.
|
powder_blower (@samuelchenardlovesboards) Chris Davis (@chrisda) - The validation warnings must be cleared and the CLA signed before we can merge this PR. |
Summary
pcttag from copyable records and rollout guidanceaction=pct.*values, but label them as legacy behaviorWhy
RFC 9989 and RFC 9990 were published in May 2026 and obsolete RFC 7489. RFC 9989 removed
pctafter operational experience showed that partial percentages were not applied consistently. The existing article still recommends a 10/25/50/75/100 percentage rollout, which can give administrators a false sense that enforcement affects only the requested sample.The replacement guidance stages enforcement by domain and observed aggregate-report results. It also explains the new
t=ytesting signal without treating it as a delivery-impact guarantee for receivers that have not implemented RFC 9989.User impact
Microsoft 365 administrators get copyable DMARC records that conform to the current Standards Track specification and a rollout procedure that does not depend on retired behavior.
Validation
ttag definitiongit diff --check