Re: EAI and ADSP/DMARC

"John Levine" <[email protected]> 12 Sep 2012 01:36:04 -0000
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
>Now the submitting MUA, will receive the bounce, and the MUA or the user may decide to provide
>an ASCII compatible email message, to be transmitted all the way. The RFCs do not seem to
>indicate specific ways to do a downgrade so that an International email can be converted into
>an ascii one and sent. It is left to the user may be with some help from its MUA to do this
>work.

That's deliberate.  The experimental predecessor to EAI tried to do
parallel EAI and ASCII addresses with automatic downgrade, and it was
an unworkable mess. See RFC 5504.

>However what I see is the possibility, for the MUA to use the group syntax in the From: header
>and submit that to the MTA to deliver to the final MTA.
>
>If my understanding is correct, this is an issue because the receiving MTA will not have
>enough information to provide a check using ADSP or DMARC. This case should not be allowed.

You can always reject mail you don't like.  ADSP is a failure, DMARC
will never apply to all mail.  We are not going to change the way that
mail works to make it match the security approach du jour.  That means
we're not going to make all mail DMARC-compatible any more than we got
rid of mail relays to make SPF happy.

If bad guys wanted to send mail with null groups on the From: line,
their spamware would be doing so right now.  What do you think will
change to make them start doing that in the future?  Surely nobody
imagines that spammers wait for the IETF to give them permission to
send stuff.  

Null groups on the From: line solve a specific EAI problem, and don't
enable any new evil that doesn't already exist in practice.

R's,
John

PS:
>Did I miss something?

Yes.
_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822