Skip to content

Home Topics Email Authentication ARC

Email Authentication · ARC

ARC (Authenticated Received Chain) and Spam Act 2003 compliance in the Australia

Short answer

The Spam Act requires consent, sender identification, and a functional unsubscribe in every commercial message. ARC (Authenticated Received Chain) supports compliance by making sender identity verifiable and recipient choices enforceable.

What Spam Act 2003 requires#

The Spam Act requires consent, sender identification, and a functional unsubscribe in every commercial message.

What ARC (Authenticated Received Chain) is#

ARC preserves authentication results across intermediaries such as mailing lists and forwarders. Each hop signs the results it saw, so the final receiver can trust an earlier pass even if SPF or DKIM broke in transit.

Why it matters#

Forwarding and mailing lists are the largest source of legitimate DMARC failures. ARC lets receivers accept mail that would otherwise be quarantined under p=reject.

How ARC (Authenticated Received Chain) supports Spam Act 2003 compliance#

Regulators and recipients need to identify who sent a message and trust that opt-out mechanisms work. ARC (Authenticated Received Chain) contributes by forwarding and mailing lists are the largest source of legitimate DMARC failures. ARC lets receivers accept mail that would otherwise be quarantined under p=reject.

Implementation steps#

  1. Check whether your inbound gateway or mailing-list software supports ARC sealing.
  2. Enable ARC sealing on any system that modifies and re-sends mail.
  3. Verify ARC-Seal, ARC-Message-Signature, and ARC-Authentication-Results headers appear on forwarded mail.
  4. Confirm downstream receivers (Gmail, Microsoft) honor your seals by checking Authentication-Results for arc=pass.

Frequently asked questions#

Do I need ARC as a sender?

No. ARC is implemented by intermediaries and receivers. Senders benefit indirectly when their mail is forwarded.

Which providers honor ARC?

Gmail, Microsoft, and Yahoo all evaluate ARC when deciding whether to override a DMARC failure.

Analyse your own setup

All analysers
Technical analysis

SPF record analyser

Parse an SPF record, count its DNS lookups, and find what will break it.

Runs in your browser
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser
Technical analysis

DKIM key analyser

Check a DKIM public key's strength, revocation state, and tags.

Runs in your browser

Keep reading on ARC