Washington, D.C. – July 24, 2026 – fTLD Registry Services (fTLD), the domain authority for .Bank and .Insurance—the exclusive domain extensions for banks, insurers, and producers—today announced a major security enhancement to protect financial organizations from email-based threats.
Following fTLD’s multi-year efforts, the Internet Engineering Task Force’s (IETF) DMARC Working Group published IETF RFC 9091 in July 2021 and fTLD supported a subsequent effort leading to the publication of RFC 9989 in May 2026. RFC 9989 includes the DNS Tree Walk, which means a mail receiver (e.g., Google, Microsoft) checks for a DMARC record at the second-level domain (SLD) (e.g., register.bank) or a lower level if relevant. If not found, it checks higher levels, such as the top-level domain, until it finds a record. More details are available in RFC 9989, Section 4.10, on the DNS Tree Walk.
The IETF’s publication of RFC 9989 formalizes a new Email Authentication (EA) technical standard that mail receivers use to implement Public Suffix Domain DMARC (PSD DMARC), thereby benefiting .Bank and .Insurance.
How PSD DMARC Benefits .Bank and .Insurance
This enhancement adds a powerful, top-level layer of protection for .Bank and .Insurance domains, making it significantly harder for cybercriminals to spoof emails, keeping financial organizations and their customers protected against phishing and online fraud.
“In over a decade of operations, fTLD has never had a confirmed case of domain name abuse due to our verification and Security Requirements, and that security is now made even stronger with PSD DMARC,” said Craig Schwartz, President of fTLD Registry Services. “fTLD’s published DMARC record improves trust in the top-level domains, helps reduce online fraud and phishing, provides security at the ecosystem level, and supports trusted email operations at scale.”
Committed to Domain Security for the Financial Services Sector
Throughout its history, fTLD has collaborated with experts in cybersecurity, domain and email security, major email service providers (such as Google and Microsoft), national governments, law enforcement agencies, and the banking and insurance sectors to develop robust Security Requirements. These standards actively mitigate threats such as phishing, spoofing, cybersquatting, and man-in-the-middle attacks. By periodically evolving its Security Requirements and defense strategies to address emerging risks, fTLD ensures that .Bank and .Insurance remain safe and trusted digital identities for the financial services sector and its customers.
About fTLD Registry Services
fTLD Registry Services is the domain authority for .Bank and .Insurance—the exclusive domain extensions for banks, insurers, and producers. Since 2011, fTLD Registry has pioneered domain innovation and security by collaborating with experts in cybersecurity, domain security, and the banking and insurance sectors to operate the trusted and most secure domains on the internet. Learn more at https://fTLD.com/.