EAI and ADSP/DMARC
Franck Martin <[email protected]> Tue, 11 Sep 2012 23:59:19 +0000
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <CC751E7D.5AA03%[email protected]> |
I'm moving all the threads away from EAI last call, as I think I feel better with the current last call documents. I have been advised to also post to [email protected]. So apologies, if I cross post and you miss a bit of history. So I read RFC6530 and I'll try to resume my understanding. No MTA talking to another MTA will downgrade or upgrade an email. If the receiving MTA cannot handle UTF8, then the email will be bounced. Now the submitting MUA, will receive the bounce, and the MUA or the user may decide to provide an ASCII compatible email message, to be transmitted all the way. The RFCs do not seem to indicate specific ways to do a downgrade so that an International email can be converted into an ascii one and sent. It is left to the user may be with some help from its MUA to do this work. However what I see is the possibility, for the MUA to use the group syntax in the From: header and submit that to the MTA to deliver to the final MTA. If my understanding is correct, this is an issue because the receiving MTA will not have enough information to provide a check using ADSP or DMARC. This case should not be allowed. That a receiving MTA downgrade the From: into a group syntax for the MUA to be able to display the email to the end user, is an annoyance in terms of ADSP/DMARC but as mentioned the fix is for the end user to upgrade its MUA. ADSP/DMARC would have already been applied to the email at this stage, so no core functionality would be lost in that transaction. The MTA would also have added Authentication-Results: header with the necessary information to indicate the result of SPF, DKIM, ADSP, DMARC. However this header is not easily visible to the end user. The DMARC spec can alert people about this case in Security Considerations, i.e. We could live with it. So in summary, my opinion is that a submitting MUA MUST NOT be allowed to use the group syntax when submitting an email to an MTA. Corrolary a MTA MUST not accept an email where the From: header contains the group syntax and should bounce that email. I think this course would keep the security benefits that ADSP/DMARC provide to the email environment. Did I miss something? This opinion is not the opinion of the DMARC group nor my company, etc… this is an individual submission as anything IETF related. _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822