Skip to content
Signet
Blog

A history of email, sourced: 1971 to DMARCbis

Email is older than the internet it now runs on. It was built for a small network of people who trusted each other, and most of its history since has been adding the proof of identity it was never given.
7 min read

Before the network

Shared computers had mail before networks did. Users of a time-sharing system could leave messages for each other on the same machine; MIT’s CTSS is usually cited, around 1965 (a secondary source, so treat the exact date with care). That was mail between accounts, not between computers.

1971: the first message between machines

In 1971, Ray Tomlinson at BBN joined two programs: SNDMSG, which left messages for users on one computer, and CPYNET, which copied files between computers on the ARPANET. The result sent a message from one machine to another. To say which user on which machine, he chose the @ sign to separate the person from the host (Internet Hall of Fame).

The 1970s: agreeing on the headers

Through the 1970s the ARPANET community wrote down what a message should look like. RFC 561 (1973) standardised headers; RFC 680 (1975) proposed more; RFC 733 (1977) replaced them with a single standard for ARPA network text messages (RFC 733). The fields you still see today, From, To, Subject and Date, come from this period.

1982: SMTP and the message format

In August 1982 two documents set the shape email still has. RFC 821, by Jonathan Postel, defined the Simple Mail Transfer Protocol: how servers hand mail to each other (RFC 821). RFC 822, by David Crocker, defined the message format (RFC 822). One describes the envelope and the conversation; the other describes the letter inside.

Four years later, RFC 974 (1986) tied mail to the Domain Name System with MX records, so a domain could name the servers that receive its mail (RFC 974). That is still how every message finds its destination.

Nothing in these standards checked who a sender was. On a network of research institutions, nobody needed it to.

Growing up: extensions and revisions

SMTP grew by extension rather than replacement. RFC 1869 (1995) introduced EHLO, letting a server advertise what it supported; RFC 3207 (2002) added STARTTLS for encrypting the connection. The core documents were revised in 2001 and again in 2008, as RFC 5321 and RFC 5322, which are the versions in force today (RFC 5321, RFC 5322).

The 2000s: retrofitting identity

As email became the internet’s front door, forged senders became its most common abuse. The answer arrived in layers, each added on top of a protocol that could not be changed underneath:

YearWhat arrivedWhat it added
2006SPF, RFC 4408A list of servers allowed to send for a domain
2007DKIM, RFC 4871A cryptographic signature tied to a domain
2012DMARC announcedA policy tying both to the visible From domain
2015DMARC, RFC 7489Published, as an Informational RFC
2018MTA-STS, RFC 8461Encryption a sender must not skip

DMARC came out of industry rather than a standards committee: a consortium of mailbox providers, banks and security firms, including AOL, Comcast, Gmail, Hotmail, Yahoo! Mail, Bank of America, Facebook, PayPal and LinkedIn, announced it in January 2012 (dmarc.org).

The 2020s: from optional to required

For most of its life, authentication was good practice that receivers rewarded. That changed when the largest mailbox providers made it a condition of delivery. In October 2023 Google and Yahoo announced that, from February 2024, bulk senders would need SPF, DKIM and a DMARC policy (Google). Microsoft followed for Outlook.com: from 5 May 2025, high-volume senders that fail the requirements are rejected (Microsoft).

And in May 2026, DMARC itself became an internet standard. RFC 9989, with RFC 9990 and RFC 9991 for reporting, replaced the eleven-year-old Informational RFC 7489 (RFC 9989). What changed in it is the subject of our post on the standards, one by one.

Half a century on, the protocol Tomlinson’s message started is still running. What changed is that a receiver can now ask whether the From line is true. See what your domain answers.

Sources

  1. Internet Hall of Fame: Raymond Tomlinson
  2. Wikipedia: History of email (pre-network mail)
  3. RFC 561, 680, 733: early ARPANET mail
  4. RFC 821: Simple Mail Transfer Protocol (1982)
  5. RFC 822: Standard for ARPA Internet Text Messages (1982)
  6. RFC 974: Mail Routing and the Domain System (1986)
  7. RFC 5321 and RFC 5322 (2008)
  8. dmarc.org: History of DMARC
  9. Google: New Gmail protections for a safer, less spammy inbox (October 2023)
  10. Microsoft: Outlook's new requirements for high-volume senders
  11. RFC 9989: DMARC (2026)

See it on your own domain. The scan reads all twelve record types in one lookup, free and without an account.

Scan a domain