The recently updated IETF’s “Applicability Statement for Core Email Protocols” (draft-ietf-emailcore-as) is reshaping email infrastructure. Now in its 23rd revision, this Internet-Draft isn’t just another technical specification—it’s a strategic blueprint for defending against today’s sophisticated email threats
This draft, which has progressed through more than 20 revisions to its current state (draft-ietf-emailcore-as-23), consolidates and clarifies best practices for the internet’s most critical communication channel. It’s the IETF’s answer to a crucial question: what does a truly secure and reliable email system look like today?
The Modern Mandate for Email Security
The EMAILCORE Applicability Statement provides a holistic view of email security, addressing the critical interplay between transport-level and message-level protections. It establishes a clear, forward-looking baseline for MTA operators and security professionals, covering:
- Enforced Transport Layer Security (TLS): The era of opportunistic STARTTLS is ending. The draft highlights the move towards robust, enforced confidentiality through MTA-STS (Mail Transfer Agent Strict Transport Security) and DANE (DNS-Based Authentication of Named Entities). While adoption of these standards remains a work in progress, it’s gaining momentum. A recent analysis from September 2025 showed that while only a small percentage of domains have implemented MTA-STS, a significant portion of total email volume is now protected by it, largely driven by major providers like Gmail and Outlook. The trend is clear: the industry is moving from optional encryption to mandatory, verifiable transport security.
- Message-Level Authentication: The document provides definitive guidance on the implementation of SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance). These protocols are no longer optional “best practices” but are now foundational requirements. According to a Valimail report, the updated 2024 bulk sender requirements from Google and Yahoo drove over half a million new DMARC implementations in the first two months of 2024 alone, demonstrating how major players are effectively pushing for a more secure ecosystem.
- Authenticated Received Chain (ARC): The importance of ARC is often underestimated. As DMARC enforcement becomes the norm, the draft clarifies ARC’s vital role in preserving authentication results across legitimate forwarding services and mailing lists. This prevents valid emails from being erroneously rejected due to a DMARC failure caused by a forwarding-induced header change. The recommendation is straightforward: if you operate an email relay, ARC is an essential component for maintaining a trusted chain of custody.
Why This Draft is Your Immediate Priority
For email experts, this document is not simply a distant future concern; it’s already very much a usable tool for today.
- Direct Response to a Growing Threat: The security stakes have never been higher. Phishing remains the top initial access vector for cyberattacks, with over 3.4 billion phishing emails sent daily and the average cost of a phishing-related data breach now a staggering $4.88 million. The rise of AI-powered attacks and “zero-day” phishing pages means attackers are innovating faster than ever. This IETF draft provides a structured, standards-based framework to combat these precise threats.
- Anticipating Evolving Requirements: The Applicability Statement signals the direction of future RFCs. By aligning your systems with its guidance now, you’re not just improving security; you’re building a future-proof infrastructure that will meet forthcoming compliance and interoperability requirements.
- A Guide to Interoperability and Deliverability: Adherence to these modern standards is increasingly tied to deliverability. Mailbox providers are already using these signals to filter incoming mail. A system that correctly implements MTA-STS and DMARC with an enforced policy is far more likely to have its legitimate emails land in the inbox.
Actionable Recommendations for Professionals
The message is clear: the time for a passive approach to email security is over. Here are the immediate steps you should take:
- Audit Your Transport Policies:
- Review your current MTA configurations. If you are not using MTA-STS or DANE, begin planning your implementation now. Start in
testingmode to gather data and identify any potential issues before moving to anenforcepolicy. - For those already using these protocols, conduct regular checks to ensure your policies are valid and your TLS certificates are correctly configured. A recent survey found that a significant number of MTA-STS policies are invalid due to configuration errors.
- Review your current MTA configurations. If you are not using MTA-STS or DANE, begin planning your implementation now. Start in
- Strengthen Your Authentication Strategy:
- Validate your DMARC implementation. If you are still at a
p=nonepolicy, this is the time to gather data and build a plan to move toquarantineorreject. The draft makes it clear that full protection requires an enforcement policy. - If your organization acts as a forwarding service, ensure your systems correctly implement ARC to preserve authentication headers and maintain a high level of trust for your users.
- Validate your DMARC implementation. If you are still at a
- Stay Engaged with the Standard:
- Monitor the progress of
draft-ietf-emailcore-ason the IETF Datatracker. Participate in the EMAILCORE working group’s mailing list discussions if you have insights to share. Your experience can directly influence the final standard.
- Monitor the progress of
The IETF’s EMAILCORE Applicability Statement represents a pivotal moment for the email ecosystem. It is a call to action to move beyond the legacy, “good enough” model of email and embrace a future where security is a fundamental design principle. By taking these steps now, email professionals can ensure their systems are not just compliant, but truly resilient against the threats of today and tomorrow.








