Organizational domain & the DNS tree walk
When a subdomain (e.g. mail.example.com) has no _dmarc record of its own, DMARC falls back to whatever its organizational domain published — typically via that domain's sp= tag. Classic DMARC (RFC 7489) determined the organizational domain using the Public Suffix List (PSL), a community-maintained list of registrable domain suffixes.
RFC 9989 §4.10 replaces PSL-based lookup with a DNS Tree Walk: query _dmarc.<domain>, and if it lacks a psd= tag, strip the left-most label and query the parent, repeating until a record with psd=n or psd=y is found or the walk runs out of labels (capped at 8 queries as an anti-abuse measure). This tool's health check implements that algorithm directly rather than depending on an external PSL.
What changed on this dashboard: previously, a domain with no _dmarc record of its own always showed a flat fail on the health check's DMARC row. Now, if an ancestor domain's record actually covers it, the row shows info instead — "inherits policy from organizational domain X" — since that's a normal, fully valid DMARC deployment pattern (most organizations only publish a record at the apex), not a problem to fix. A domain genuinely uncovered anywhere in its ancestry still shows fail exactly as before.
- RFC 9989 §4.10
- RFC 9989 §4.10.2