Re: EAI and ADSP/DMARC

Franck Martin <[email protected]> Wed, 12 Sep 2012 18:17:13 +0000
Newsgroups gmane.ietf.rfc822
Message-ID <CC761EDF.5B40E%[email protected]>

On 9/12/12 5:55 AM, "Barry Leiba" <[email protected]> wrote:

>> Yes, I can always reject mail I don't like, but I doubt this will fly if
>> we add that in the DMARC spec and hand it over to IETF.
>
>If/when DMARC comes into the IETF, you will have the same endless
>arguments about that as in the DKIM/ADSP and SPF work about what who
>can tell whom to do with messages and how.  John isn't saying that
>*DMARC* will or should reject anything.  DMARC will simply say call
>this a validation failure, just as it would if there were a fake From
>address in the message.  John's saying that any MTA can choose to
>reject such a message, because it doesn't like group syntax in From or
>for any other reason.
>
>There's already an applicability statement in here that says this is
>for essential uses and no others, and there's a warning in the
>Security Considerations that misuse can result in non-delivery of
>mail.  What you're concerned about is already addressed.

I think the impression is that DMARC is like the SPF -all or ADSP, just a
flag for the reputation engine down the stream.

A correct implementation of DMARC will reject emails at the edge as per
sender policies. This is very safe to do for the receiver because of all
the feedback mechanisms to the sender. Exceptions to the rule are also
documented in the feedback mechanisms.

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822