THE MACHINE THRESHOLD
Cybersecurity / EXPLAINER / 2 MIN READ + OPTIONAL DEEP DIVE

An email passes authentication. Is its message trustworthy?

Domain checks can validate a sender’s domain without verifying the person, the request or the story.

AI-assisted synthesis · Published 2026-09-21 · Updated & sources checked 2026-09-21
How we research and correct our work

Authentication is useful evidence, but its meaning is narrower than the familiar name at the top of an email.

It answers a narrower question

A DMARC pass validates authorized use of an email’s author domain; it does not certify that the message is safe. The current DMARC specification explicitly separates domain validation from a judgment about the message. A familiar display name is another question again. [2]

Do not merge three separate questions
  1. Display name: who it appears to be
  2. Domain: whose use was validated
  3. Request: whether it is legitimate
A domain pass is not a verdict on the message

Three tools, related jobs

The FTC describes Sender Policy Framework (SPF) as checking whether a server may send for a domain, and DomainKeys Identified Mail (DKIM) as checking a digital signature. Domain-based Message Authentication, Reporting, and Conformance (DMARC) connects a passing SPF or DKIM result to the domain in the visible From address through an alignment check. [1] [2]

What the check leaves open

The May 2026 standard says DMARC does not address lookalike domains or deceptive display names. Receiving services also retain discretion over how to handle messages. The FTC advises getting knowledgeable help with configuration so legitimate mail is not accidentally blocked. This is an explanation of scope, not a setup recipe. [1] [2]

Go a little deeper

Optional reading · about 1 more minute

A name is not a domain

Hypothetical example: A message displays “Studio Accounts” but comes from a domain your studio has never used. Even if that domain authenticates its own mail, the result does not establish a relationship with your studio. Keep the sender’s label, the domain and the requested action as three separate questions.

Use evidence suited to the request

Our interpretation: When a message asks you to change an established process, seek confirmation through a contact route you already trust. A technical pass result should support your assessment, not replace the evidence that this particular request is legitimate.

Original sources

Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.

  1. FTC: email authentication for small business ↗

    September 2025 guidance. Email Authentication section reopened September 21, 2026. Mechanism overview, not a new incident report.

  2. RFC 9989: current DMARC specification ↗

    May 2026 Proposed Standard; reviewed September 21. Replaces RFC 7489 and RFC 9091. Introduction and anti-phishing scope checked; this article gives no deployment configuration.

Suggest a correction

Know someone who would find this interesting?

Share this story on Facebook ↗ ·

Follow on Facebook ↗ for story highlights and questions to explore next.

Where this question leads next

Follow new explainers and updates →