the DMARC market has a coverage problem nobody talks about
most DMARC vendors monitor 3-5 protocols: DMARC, SPF, DKIM, maybe BIMI, maybe MTA-STS
ARC (RFC 8617) matters because mailing lists and forwarding break DKIM
DANE (RFC 7671) matters because it pins TLS certificates via DNSSEC
TLS-RPT (RFC 8460) matters because you need to know when encrypted delivery fails
if you're monitoring half the stack, you're monitoring half the picture
