Home / Insights / Email Standards Based on RFCs
Email Standards Based on RFCs: A Practical Reference
Anil Jalela · Published Apr 7, 2021 · 15 min read
On this page How to use this RFC index The core Internet email stack SMTP transport, submission, and delivery extensions Message format, MIME, headers, and identifiers Delivery reports, receipts, automatic responses, and abuse feedback SPF, DKIM, DMARC, ARC, and authentication results Transport security and end-to-end protection IMAP, POP3, and mailbox synchronization JMAP mail and related extensions Sieve filtering and server-side rules Internationalized email and addresses Mailing lists, unsubscribe, role addresses, and bulk operations Discovery, authentication frameworks, and supporting protocols Specialized email RFC families Obsolete RFC numbers still found in documentation Standards that are not RFCs How to maintain an email standards baseline Internet email is not defined by one RFC. A message crosses standards for addressing, submission, transfer, DNS routing, content structure, authentication, encryption, mailbox access, filtering, delivery reports, and list management. When somebody says a system is “RFC compliant,” the useful follow-up is simple: which RFC, which extension, and has a newer document changed it?
This reference groups the RFCs that define or materially affect general Internet mail operations. It includes the active core, widely implemented extensions, security and reporting specifications, newer 2024 to 2026 work, and the obsolete RFC numbers that still appear in products and documentation. Specialized MIME registrations, historic ARPANET memoranda, X.400 gateways, fax profiles, and military messaging are summarized separately so the operational standards remain readable.
How to use this RFC index
An RFC number is not proof that a document is current or mandatory. RFCs can be Internet Standards, Proposed Standards, Best Current Practices, Informational documents, Experimental documents, or Historic documents. A later RFC can update part of a specification without replacing the whole document, or obsolete it completely.
Open the RFC Editor information page and check its status, errata, updates, and obsoletes relationships.
Use the matching IANA protocol registry for live extension names, parameters, header fields, status codes, and assigned values.
Separate protocol conformance from provider policy. A message can follow the RFCs and still be filtered because of reputation, consent, abuse, or content signals.
Test the complete path. Sender behavior, intermediaries, receivers, and clients can implement different subsets of the same extension family.
The core Internet email stack
RFC Standard Operational role
RFC 5598 Internet Mail Architecture Defines the roles used across message submission, transfer, delivery, access, and administration.
RFC 5321 Simple Mail Transfer Protocol Core SMTP transfer, envelopes, commands, reply handling, routing, retries, and trace behavior.
RFC 6409 Message Submission for Mail Separates authenticated client submission from server-to-server relay and defines the submission service.
RFC 5322 Internet Message Format Defines the message header section, fields, addresses, dates, identifiers, and body boundary.
RFC 2045 , RFC 2046 , RFC 2047 , and RFC 2049 MIME Adds media types, transfer encodings, multipart bodies, non-ASCII header text, and conformance rules.
RFC 9051 IMAP4rev2 Current IMAP base for remote mailbox access and synchronization. It obsoletes RFC 3501.
RFC 1939 POP3 Defines the simpler download-oriented mailbox access protocol still used by many systems.
RFC 8620 and RFC 8621 JMAP Core and JMAP for Mail Defines a JSON-based API model and its mail data, query, state, and submission capabilities.
RFC 6186 Email service discovery Uses DNS SRV records to locate submission, IMAP, and POP services.
RFC 8314 TLS for submission and access Treats cleartext email submission and access as obsolete and recommends TLS-protected services.
SMTP transport, submission, and delivery extensions
The IANA SMTP registry is the live source for registered EHLO keywords, parameters, verbs, transmission types, enhanced status codes, and server-limit names.
RFC Extension or practice Why an operator uses it
RFC 1870 SIZEAdvertises message-size limits and lets a sender declare the estimated message size.
RFC 1985 ETRNRequests remote queue processing for intermittently connected systems.
RFC 2034 Enhanced error codes in SMTP replies Adds structured status detail to SMTP responses.
RFC 2505 Anti-spam recommendations for MTAs Historic but still useful operational guidance for relay control, traceability, and abuse handling.
RFC 2645 On-Demand Mail Relay Supports queued delivery to systems with dynamic addresses.
RFC 2852 DELIVERBYCommunicates a delivery-time requirement or expiry condition.
RFC 2920 PIPELININGAllows specified SMTP commands to be sent without waiting for every individual response.
RFC 3030 CHUNKING and BINARYMIMETransfers message data in chunks and supports binary MIME when both sides agree.
RFC 3207 STARTTLS for SMTPUpgrades an SMTP connection to TLS. Policy enforcement requires additional standards.
RFC 3461 Delivery Status Notification extension Defines RET, ENVID, NOTIFY, and ORCPT negotiation.
RFC 3463 and RFC 5248 Enhanced mail status codes and registry Standardizes the X.Y.Z diagnostic model and its assigned code space.
RFC 3848 ESMTP and LMTP transmission types Registers values used in Received trace fields.
RFC 4468 Submission BURL Lets an authorized submitter reference message data by URL instead of uploading it again.
RFC 4865 FUTURERELEASERequests that a submission server hold a message until a future time.
RFC 4954 SMTP AUTH Advertises and performs SASL authentication for message submission.
RFC 5068 Submission operations Best Current Practice for access, accountability, authentication, and traceability.
RFC 6152 8BITMIMEAllows transport of MIME bodies containing 8-bit data when advertised.
RFC 6531 SMTPUTF8Extends SMTP for internationalized addresses and UTF-8 message headers.
RFC 6710 MT-PRIORITYCommunicates message-transfer priority in environments that implement it.
RFC 7293 RRVSHelps detect delivery to an address that was reassigned after a known date.
RFC 7504 SMTP 521 and 556 replies Signals that a host or domain does not accept mail.
RFC 7505 Null MX Lets a domain state explicitly that it accepts no email.
RFC 8689 REQUIRETLSAllows a sender to require TLS-protected relay for a message rather than accept opportunistic downgrade.
RFC 9422 LIMITSAdvertises implementation limits such as command, recipient, and transaction constraints.
RFC Area What it defines
RFC 5322 and RFC 6854 Internet Message Format Core header and body syntax, with the later update for group syntax in From and Sender.
RFC 2045 MIME bodies and transfer encodings MIME-Version, content types, quoted-printable, Base64, and body format.
RFC 2046 MIME media types Text, image, audio, video, application, message, and multipart behavior.
RFC 2047 Encoded words Non-ASCII display text in applicable message header fields.
RFC 2049 MIME conformance Implementation requirements and examples for MIME-capable agents.
RFC 2183 Content-DispositionInline and attachment presentation plus filename parameters.
RFC 2231 MIME parameters Character sets, languages, extended parameter values, and continuations.
RFC 2387 multipart/relatedGroups a root body with resources such as inline images.
RFC 2392 cid: and mid: URLsReferences MIME body parts and messages by content or message identifier.
RFC 2557 MHTML Encapsulates aggregate HTML documents and related resources in MIME.
RFC 3676 format=flowedSupports flowed plain text and quote handling.
RFC 4021 and RFC 4249 Header registration and implementation map Catalogs mail and MIME header fields and describes their components.
RFC 4289 and RFC 6838 Media-type registration Defines registration procedures used by MIME media types.
RFC 6068 mailto: URIDefines mail composition links and their permitted fields and encoding.
RFC 6532 Internationalized headers Permits UTF-8 in message header field values within the EAI framework.
RFC 6657 Text charset handling Updates MIME guidance for the charset parameter.
RFC 9228 Delivered-ToExperimental registration and processing guidance for a commonly seen delivery header.
Delivery reports, receipts, automatic responses, and abuse feedback
RFC Report or behavior Use
RFC 3461 , RFC 3463 , and RFC 3464 Delivery Status Notifications Negotiates DSNs, standardizes status codes, and defines the machine-readable delivery-status format.
RFC 6522 multipart/reportCurrent base media type for administrative mail reports. It obsoletes RFC 3462.
RFC 6533 Internationalized DSN and MDN Extends report formats for internationalized addresses and UTF-8 content.
RFC 8098 Message Disposition Notification Current read, display, delete, and disposition receipt format. It obsoletes RFC 3798.
RFC 3834 Automatic responses Defines safe behavior and the Auto-Submitted field to reduce loops.
RFC 5965 Abuse Reporting Format Defines machine-readable email feedback reports used by complaint and abuse systems.
RFC 6430 not-spam feedback typeReports that a message was incorrectly classified as spam.
RFC 6590 ARF redaction Redacts sensitive data from abuse reports while retaining useful evidence.
RFC 6591 Authentication failure reports Defines ARF fields for email authentication failures; RFC 9991 supplies current DMARC failure-reporting rules.
RFC 6650 ARF applicability Operational guidance for creating and consuming feedback reports.
RFC 6651 and RFC 6652 DKIM and SPF failure reporting Defines failure-reporting extensions for DKIM and SPF.
RFC 6692 Source ports in ARF Adds source-port information when it is relevant to a report.
RFC 7372 Email authentication status codes Registers enhanced status codes for authentication-related failures.
RFC 9990 DMARC aggregate reporting Defines the current aggregate feedback format and processing model.
RFC 9991 DMARC failure reporting Defines current message-specific DMARC failure reporting.
SPF, DKIM, DMARC, ARC, and authentication results
RFC Control What it proves or records
RFC 7208 SPF Checks whether the connecting source is authorized for an SMTP identity. It does not authenticate the visible From field by itself.
RFC 6376 DKIM Associates a signing domain with selected header fields and the body through a verifiable signature.
RFC 5585 and RFC 5863 DKIM overview and operations Explains DKIM service roles, deployment choices, signing, verification, and operational tradeoffs.
RFC 6377 DKIM and mailing lists Best Current Practice for signature survival and list transformations.
RFC 8301 DKIM algorithm and key update Raises cryptographic requirements and removes weak choices.
RFC 8463 Ed25519 for DKIM Adds an alternative DKIM signature method where implementations support it.
RFC 8601 Authentication-ResultsRecords trusted receiver results for SPF, DKIM, DMARC, ARC, and other registered methods.
RFC 8616 Authentication for internationalized mail Updates SPF, DKIM, and authentication results for SMTPUTF8 messages.
RFC 8617 ARC Creates an authenticated chain of message handling and prior authentication results across intermediaries.
RFC 7960 DMARC and indirect flows Explains forwarding and mailing-list interoperability failures.
RFC 9989 DMARC Current DMARC protocol and policy specification. It obsoletes RFC 7489 and RFC 9091.
RFC 9990 and RFC 9991 DMARC reporting Separate current specifications for aggregate and failure reporting.
BIMI is not an RFC. BIMI is an industry specification that uses DNS, SVG, DMARC enforcement, and in some deployments a mark certificate. It belongs in an authentication and brand-assurance review, but it should not be presented as an IETF RFC.
Transport security and end-to-end protection
RFC Security layer Purpose
RFC 3207 SMTP STARTTLS Negotiates TLS on SMTP connections.
RFC 7817 Email TLS identity checks Updates certificate-name checking for SMTP, IMAP, POP3, and related services.
RFC 8314 and RFC 8997 Submission and access TLS Recommends encrypted submission/access and deprecates TLS 1.1 for those services.
RFC 6698 , RFC 7671 , and RFC 7672 DANE and SMTP Uses DNSSEC-protected TLSA records to authenticate SMTP TLS and resist downgrade.
RFC 8461 MTA-STS Publishes an HTTPS policy requiring authenticated TLS delivery to named MX hosts.
RFC 8460 TLS reporting Reports SMTP TLS policy and negotiation failures.
RFC 8689 REQUIRETLS Provides per-message TLS requirements through SMTP.
RFC 9846 , RFC 8996 , and RFC 9325 General TLS foundation Current TLS 1.3 base, deprecation of TLS 1.0 and 1.1, and implementation guidance for secure TLS use.
RFC 1847 and RFC 3156 Security multiparts and OpenPGP/MIME Defines signed/encrypted MIME containers and their use with OpenPGP.
RFC 8550 and RFC 8551 S/MIME 4.0 Current S/MIME certificate handling and message specification.
RFC 9580 and RFC 9980 OpenPGP Current OpenPGP format plus post-quantum cryptography extensions.
RFC 9598 Internationalized addresses in certificates Current X.509 representation for internationalized email addresses.
RFC 9787 End-to-end email security guidance Current guidance for deploying and operating encrypted and signed email.
RFC 9788 Protected headers Protects selected header fields inside cryptographically protected messages.
IMAP, POP3, and mailbox synchronization
IMAP extensions are numerous because clients need capabilities for synchronization, search, quotas, metadata, special-use folders, preview generation, and large mailboxes. The server capability response tells a client which subset is available.
RFC Capability Operator note
RFC 9051 IMAP4rev2 Current base IMAP protocol. RFC 3501 is obsolete.
RFC 1939 , RFC 2449 , and RFC 5034 POP3, extension model, and SASL Core POP3 retrieval plus extension discovery and authentication.
RFC 2177 IDLENotifies a connected client about mailbox changes without polling.
RFC 2971 IDExchanges implementation identification information.
RFC 4314 and RFC 4315 ACL and UIDPLUS Mailbox permissions and safer UID-based append, copy, and expunge workflows.
RFC 4466 Collected IMAP ABNF extensions Shared syntax used by many later IMAP extensions.
RFC 4978 COMPRESSCompresses an IMAP connection after negotiation.
RFC 5092 IMAP URI References IMAP mailboxes and messages through a URI scheme.
RFC 5161 and RFC 5182 ENABLE and SEARCHRESEnables selected extensions and reuses the last search result.
RFC 5256 and RFC 5258 SORT, THREAD, and LIST extensions Server-side organization plus richer mailbox listing.
RFC 5464 and RFC 5465 METADATA and NOTIFY Mailbox/server annotations and event notifications.
RFC 5530 and RFC 5819 Response codes and LIST-STATUS More precise failures and mailbox status during listing.
RFC 6154 Special-use mailboxes Identifies standard roles such as Sent, Drafts, Junk, and Trash.
RFC 6203 and RFC 7377 Fuzzy and multimailbox search Improves server-side search behavior across messages and mailboxes.
RFC 6851 and RFC 7162 MOVE, CONDSTORE, and QRESYNC Moves messages and performs efficient disconnected-client synchronization.
RFC 7888 and RFC 7889 Non-synchronizing literals and APPENDLIMIT Reduces command round trips and advertises append-size limits.
RFC 8437 , RFC 8438 , and RFC 8440 UNAUTHENTICATE, STATUS=SIZE, and MYRIGHTS Connection reuse, mailbox-size status, and effective-rights reporting.
RFC 8457 and RFC 8474 Important mailbox semantics and object IDs Standard importance markers and stable mailbox/message identifiers.
RFC 8508 and RFC 8514 REPLACE and SAVEDATE Atomic message replacement and preservation of save time.
RFC 8970 and RFC 9208 PREVIEW and QUOTA Server-generated previews and current quota handling.
RFC 9394 PARTIAL Paged SEARCH and FETCH results for large result sets.
RFC 9585 , RFC 9586 , and RFC 9590 Progress, UID-only mode, and LIST-METADATA Newer progress responses, an experimental UID-only model, and metadata returned during listing.
RFC 9698 , RFC 9738 , and RFC 9979 JMAP access, message limits, and keywords JMAP service discovery from IMAP, an experimental message limit, and additional standardized keywords and mailbox attributes.
RFC 9755 IMAP UTF-8 Current IMAP UTF-8 support. It obsoletes RFC 6855.
RFC Capability Scope
RFC 8620 JMAP Core Session discovery, method calls, state, errors, uploads, downloads, and push model.
RFC 8621 JMAP for Mail Mailboxes, email objects, threads, identities, vacation responses, and submission.
RFC 8887 JMAP over WebSocket Persistent bidirectional transport for JMAP method calls and state changes.
RFC 9007 JMAP MDN Creates and processes message disposition notifications through JMAP.
RFC 9219 JMAP S/MIME verification Reports S/MIME signature verification information.
RFC 9404 and RFC 9425 Blob management and quotas Manages binary objects and exposes quota information.
RFC 9610 JMAP for Contacts Defines contacts and address books in the broader JMAP ecosystem.
RFC 9661 JMAP for Sieve scripts Creates, updates, validates, and activates Sieve scripts through JMAP.
RFC 9670 JMAP Sharing Shares JMAP data with users and groups through access controls.
RFC 9749 JMAP Web Push with VAPID Authenticates application servers that deliver JMAP push notifications.
Sieve filtering and server-side rules
The IANA Sieve registry is the live capability list. A Sieve server can implement only part of this family, so scripts must test capabilities rather than assume every extension exists.
RFC Extension Purpose
RFC 5228 Sieve base language Safe server-side mail filtering with tests, actions, and capability negotiation.
RFC 3894 , RFC 5173 , and RFC 5183 Copy, body, and environment Keeps a copy, inspects body content, and reads execution-environment values.
RFC 5229 , RFC 5231 , and RFC 5260 Variables, relational tests, and dates Adds reusable variables, comparisons, and date/index tests.
RFC 5230 and RFC 6131 Vacation responses Creates controlled auto-replies with finer response intervals.
RFC 5232 , RFC 5233 , and RFC 5235 IMAP flags, subaddresses, spam and virus tests Sets message flags, recognizes address detail parts, and consumes filtering scores.
RFC 5293 and RFC 5429 Editheader and reject Modifies permitted headers and rejects delivery with controlled responses.
RFC 5435 and RFC 5436 Notifications Defines the notification framework and its mailto mechanism.
RFC 5463 and RFC 5490 Ihave, mailbox status, and metadata Tests extension support and reads mailbox state and annotations.
RFC 5703 MIME part processing Tests, iterates, extracts, replaces, and encloses MIME parts.
RFC 5804 ManageSieve Remotely stores, lists, validates, and activates Sieve scripts.
RFC 6009 and RFC 6134 DSN, Deliver-By, and external lists Adds delivery controls and tests membership in externally stored lists.
RFC 6558 and RFC 6609 Convert and include Converts message content and composes scripts from reusable parts.
RFC 6785 and RFC 7352 IMAP events and duplicate detection Runs rules on mailbox events and identifies duplicate deliveries.
RFC 8579 and RFC 8580 Special-use delivery and file carbon copy Files into a mailbox role and keeps a copy of generated messages.
RFC 9042 and RFC 9122 MAILBOXID delivery and action registry Targets stable mailbox IDs and defines the registry for Sieve actions.
RFC 9661 and RFC 9671 JMAP script management and calendar attachments Manages scripts through JMAP and processes calendar invitations.
Internationalized email and addresses
RFC Area Requirement
RFC 5890 to RFC 5895 IDNA2008 Defines internationalized domain-name terminology, protocol, tables, directionality, and mapping guidance.
RFC 6530 EAI framework Overview and architecture for internationalized email.
RFC 6531 SMTPUTF8 Negotiates internationalized mailbox local-parts and UTF-8 headers in SMTP.
RFC 6532 UTF-8 message headers Extends Internet Message Format for internationalized header values.
RFC 6533 Internationalized reports Extends delivery and disposition notifications.
RFC 6783 Mailing lists and non-ASCII addresses Explains list interoperability with internationalized addresses.
RFC 6856 , RFC 6857 , and RFC 6858 POP3 and downgrade handling Supports UTF-8 in POP3 and defines post-delivery downgrade approaches for legacy clients.
RFC 8616 Internationalized authentication Updates email authentication methods and result fields for EAI.
RFC 9598 Internationalized certificate identities Represents internationalized email addresses in X.509 certificates.
RFC 9755 IMAP UTF-8 Current IMAP extension for internationalized mailbox names, addresses, and message handling.
Mailing lists, unsubscribe, role addresses, and bulk operations
RFC Area Use
RFC 2142 Role mailboxes Defines conventional addresses such as postmaster, abuse, and security.
RFC 2369 List command headers Defines List-Unsubscribe, List-Help, List-Post, and related fields.
RFC 2919 List-IDProvides a stable mailing-list identifier independent of posting and subscription addresses.
RFC 3834 Automatic response control Prevents vacation responders and automated systems from creating loops.
RFC 5064 Archived-AtLinks a message to a stable archive location.
RFC 6377 DKIM and list transformations Explains signature breakage and operational choices for lists.
RFC 6449 Complaint feedback loops Operational recommendations for complaint feedback handling.
RFC 6783 Internationalized lists Handles non-ASCII subscriber and posting addresses.
RFC 7960 DMARC interoperability Documents problems introduced by forwarding and content-changing lists.
RFC 8058 One-click unsubscribe Adds an HTTPS POST mechanism used with List-Unsubscribe and List-Unsubscribe-Post.
Discovery, authentication frameworks, and supporting protocols
RFC Supporting standard Email use
RFC 2782 and RFC 6186 DNS SRV and email discovery Locates submission and access services. Microsoft Autodiscover and Thunderbird autoconfiguration are separate vendor mechanisms, not IETF email RFCs.
RFC 4422 SASL Authentication framework used by SMTP AUTH, IMAP, POP3, and ManageSieve.
RFC 5802 and RFC 7677 SCRAM Password-based SASL mechanisms, including SCRAM-SHA-256.
RFC 7628 OAuth for SASL OAuth bearer authentication used by modern mail clients and providers.
RFC 9495 CAA for email addresses Defines certification authority authorization processing for email-address certificates.
RFC 8162 and RFC 8823 S/MIME certificate discovery and automation Associates certificates through DNS and extends ACME for end-user S/MIME certificates.
Specialized email RFC families
These specifications are real parts of the email standards landscape, but most general deliverability teams encounter them only in specific products or regulated environments.
RFCs Specialized family Where it appears
RFC 4155 mbox storage format Mailbox files, archives, exports, and migration tooling.
RFC 5545 , RFC 5546 , and RFC 6047 iCalendar, iTIP, and iMIP Meeting invitations and calendaring transported through email.
RFC 6109 Italian certified email Documents the Posta Elettronica Certificata system.
RFC 3191 , RFC 3192 , and RFC 3965 GSTN, fax addressing, and Internet fax Fax gateways and legacy messaging integration.
RFC 3801 to RFC 3804 Voice Profile for Internet Mail Voice-message MIME profiles and addressing.
RFC 2156 and RFC 2157 X.400 and MIME mapping Gateways between Internet mail and X.400 environments.
RFC 1767 and RFC 4130 EDI over MIME and AS2 Business document interchange using MIME and secure transport profiles.
RFC 6477 , RFC 7444 , and RFC 7912 Military and controlled-message fields Security labels, authorizing fields, and specialized message handling.
RFC 7017 Mail archive access IMAP access to IETF email-list archives.
Obsolete RFC numbers still found in documentation
Standards that are not RFCs
Several important email controls come from industry groups or providers rather than the IETF RFC stream:
BIMI: An industry specification for brand indicators. It is not an RFC.
Mailbox-provider bulk sender requirements: Gmail, Yahoo, Microsoft, and other providers publish operational policies that can be stricter than the protocol minimum.
Feedback loops and reputation portals: Provider-specific registration and data formats often sit beside, not inside, the ARF RFC family.
Autoconfiguration: Microsoft Autodiscover and Thunderbird autoconfiguration are vendor mechanisms. RFC 6186 covers the standards-based DNS SRV path.
M3AAWG guidance: Industry Best Common Practices provide operational advice but are not IETF RFCs.
How to maintain an email standards baseline
Record the exact protocol and extension advertised by each production service.
Link every implementation requirement to the current RFC Editor information page, not an old blog summary.
Check the RFC status, errata, updated-by, and obsoletes fields before treating a number as current.
Check the relevant IANA registry for live parameters, result names, header fields, status codes, and capabilities.
Separate mandatory protocol behavior from recommended operations and provider-specific policy.
Test negative cases: malformed messages, missing extensions, TLS downgrade, authentication failure, retry behavior, report loops, and unsupported UTF-8 paths.
Preserve raw messages, SMTP responses, capability advertisements, DNS answers, and server logs as evidence.
Review the baseline after MTA, mailbox, DNS, authentication, TLS, filtering, or provider-policy changes.
The RFC set is not a checklist where every server must implement every row. It is a map. Start with the core stack, add the extensions your workflow actually advertises, and document what happens when the other side does not support them. That approach is more useful than claiming broad RFC compliance without naming the behavior being tested.