Solo ads sellers / Blog / ADSP

Solo ads blog

An old author-signing policy is not DMARC

Answer An ADSP record is not a DMARC record. RFC 5617 defined Author Domain Signing Practices, an older way for a domain to say whether it signs mail with DKIM. It does not publish p=none, quarantine, or reject. A solo ad seller who points at that record and calls it DMARC is naming the wrong document.

Cream stationery and a teal accent on a dark navy desk
The old record is not the policy you think it is.

The note that started this: RFC 5617, DKIM Author Domain Signing Practices (ADSP), RFC 5617.

The month has been asking for one tag. Tomorrow's note will say that even the previous DMARC document has been replaced. Today's mistake is earlier than that. Some old guides still tell a domain owner to publish an author policy and then talk as if the modern receivers were listening to it. They are not listening to it as if it were DMARC. The receivers that enforce a policy are reading the DMARC record.

RFC 5617 is DKIM Author Domain Signing Practices. A domain could publish a practice: I sign all my mail, I might sign, or I sign everything and you should distrust unsigned mail. The idea was understandable. The deployment did not become the control mailbox providers standardized on. DMARC did. DMARC looks at alignment between the From domain and a passing SPF or DKIM identifier, then applies p=. ADSP does not do that job. Keeping an ADSP record around is not evil. Describing it as the enforcement policy is a false description, and a buyer should not pay a premium for a false description.

What is ADSP?

RFC 5617 defined Author Domain Signing Practices, a way for a domain to publish whether it signs all of its mail with DKIM. It is not DMARC. It does not use the p= policy this month's notes have been asking for.

You can ignore the record and still be a careful buyer. You cannot substitute it. If the seller's proof of authentication is a DNS name that ends in the ADSP label, ask them to open the DMARC record instead. The DMARC record is a TXT at the dmarc name under the domain. The tag you want is p=. If that lookup is empty, there is no DMARC policy, no matter how confident the old author record sounds.

This confusion shows up in recycled swipe for best solo ad vendors who inherited a checklist from a decade ago. The checklist says publish a signing policy. The person following it publishes the obsolete one, checks the box, and takes guest money. The mailbox never received the instruction they think they sent. The guest's offer then rides a domain that is unsigned in the only sense that counts.

Can a seller publish ADSP and call the domain DMARC protected?

No. An ADSP record is the wrong record. DMARC is the TXT record that carries p=none, quarantine, or reject. Calling the old policy by the new name does not make mailboxes enforce it.

Words are cheap in a pitch. DNS is checkable. Check it, or ask them to paste the exact TXT and then check it yourself before you pay. A paste can be edited. A lookup on the domain in the From line is the fact. If the paste and the lookup disagree, believe the lookup and leave.

If you sell the send, delete the old advice from the onboarding doc. Publish DMARC, even if you are still at p=none while you read reports. Tell the buyer the truth about which policy is live. Do not keep ADSP as a comfort object. Comfort objects do not survive a receiver that never asks for them.

What should a buyer require instead?

Require the DMARC record on the From domain, and require the p= value in writing. If the seller only has an author-signing policy from the old specification, the enforcement they are selling is not there.

Pair it with the live signature, because a policy without aligned mail is a policy that will punish the send once it says quarantine or reject. You want both objects. The record. The message that passes it.

Then price the drop as a drop. Solo ad pricing does not include a surcharge for a retired author policy. RFC 5617 can stay on the shelf. The record that belongs on the order is DMARC, and tomorrow's note is about which DMARC document a seller is allowed to quote.