Before there was email, there was “sneakernet” — engineers physically driving magnetic tape between buildings because computers had no way to talk to each other. Chapter 1 starts there, in the late 1960s, and ends in 2026 with DMARCbis, tracing every standard in between.

The pivot point is ARPANET, built by the US Department of Defense not for communication but for survival — a network resilient enough that data could route around a destroyed city. Email was never the plan. It was an accident that happened because one engineer, Ray Tomlinson at BBN Technologies, spent evenings and weekends in 1971 combining two unrelated tools — SNDMSG, for leaving notes on a shared machine, and CPYNET, an experimental file-copying tool — into something that could deliver a message to a mailbox on a different computer entirely. He needed a way to separate a person’s name from the machine they were on, and picked a symbol doing nothing useful on a Teletype keyboard: @. Fifty-five years later, it’s still there.

From that unauthorized side project, the chapter follows the standards that turned a hack into infrastructure: RFC 561 and RFC 680 bringing the first shared rules in 1973–75, RFC 733 and then RFC 822 defining the message format that held for two decades, SMTP arriving the same year as the transport layer, and MIME in 1992 finally letting email carry more than plain text.

The back half is the security arms race: the spam era that made authentication necessary, SPF in 2003 as the first real defense, DKIM and DomainKeys adding cryptographic proof, DMARC in 2012 tying both together with a policy, and ARC in 2019 fixing what DMARC broke for mailing lists. It closes on DMARCbis — the 2026 standard that made over a decade of de facto DMARC practice officially official — and a look ahead at DKIM2, still in development.

Read this chapter first. Everything after it makes more sense once you know why each protocol exists, not just what it does.