Re: EAI and ADSP/DMARC
Franck Martin <[email protected]> Wed, 12 Sep 2012 01:57:58 +0000
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <CC75366A.5AACE%[email protected]> |
On 9/11/12 6:36 PM, "John Levine" <[email protected]> wrote: >>Now the submitting MUA, will receive the bounce, and the MUA or the user >>may decide to provide >>an ASCII compatible email message, to be transmitted all the way. The >>RFCs do not seem to >>indicate specific ways to do a downgrade so that an International email >>can be converted into >>an ascii one and sent. It is left to the user may be with some help from >>its MUA to do this >>work. > >That's deliberate. The experimental predecessor to EAI tried to do >parallel EAI and ASCII addresses with automatic downgrade, and it was >an unworkable mess. See RFC 5504. > >>However what I see is the possibility, for the MUA to use the group >>syntax in the From: header >>and submit that to the MTA to deliver to the final MTA. >> >>If my understanding is correct, this is an issue because the receiving >>MTA will not have >>enough information to provide a check using ADSP or DMARC. This case >>should not be allowed. > >You can always reject mail you don't like. ADSP is a failure, DMARC >will never apply to all mail. We are not going to change the way that >mail works to make it match the security approach du jour. That means >we're not going to make all mail DMARC-compatible any more than we got >rid of mail relays to make SPF happy. Yes, I can always reject mail I don't like, but I doubt this will fly if we add that in the DMARC spec and hand it over to IETF. By the way the statement DMARC will never apply to all mail, is a bold statment. Today it mainly applies to domains with a phishing problem, but tomorrow? I don't see any limitations for DMARC to apply to all emails. If I'm not mistaken, DMARC Filtering has been strictly implemented by Google, Yahoo, AOL, Netease, XS4ALL, Facebook, LinkedinÅ These are lot of protected mailboxes today. There is certainly a strong momentum for DMARC. > >If bad guys wanted to send mail with null groups on the From: line, >their spamware would be doing so right now. What do you think will >change to make them start doing that in the future? Surely nobody >imagines that spammers wait for the IETF to give them permission to >send stuff. Just because today they don't have to, better techniques work for spamming, does not mean they won't in the future. The EAI group is changing the way the email standard has been defined for exchanging email between MTA by allowing the group notation in the From: header. I consider this change decreasing security not improving it. _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822