Re: Mailing lists - assumptions

Scott Kitterman <[email protected]> Sat, 19 Apr 2014 23:45:33 -0400
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
On April 19, 2014 10:44:45 PM EDT, S Moonesamy <[email protected]> wrote:
>Hi Ned,
>At 15:33 19-04-2014, Ned Freed wrote:
>>Given that this issue is a forseeable - and forseen - consequence of 
>>using SPF,
>>and given there's an effective, but not exactly obvious, solution to
>the
>>problem, why are we going forward with publication of SPFBIS as a
>proposed
>>standard (currently in AUTH48) without a companion document describing
>this
>>problem and at least the corresponding solution space, if not going so
>far as
>>to document a specific solution?
>
>The document is moving forward because that is what the IETF agreed 
>to.  I suggest discussing the matter with Pete Resnick as soon as 
>possible if there is a serious issue that has been missed.
>
>This is from https://help.yahoo.com/kb/mail/SLN24016.html
>
>'This means all DMARC compliant mail receivers (including Yahoo,
>Hotmail,
> and Gmail) are now bouncing emails sent as "@yahoo.com" addresses that
>aren't sent through Yahoo servers. Any messages without a proper Domain
> Keys Identified Mail (DKIM) signature or Sender Policy Framework (SPF)
>    alignment will be rejected.
>
>ESPs who use their customers' "@yahoo.com" address as the "From"
>address
>    to send messages are impacted by this change.'
>
>People might read the about as messages which pass DKIM or SPF will 
>not be rejected.  That's not what those mail receivers are doing.

Right. I think it bears repeating for emphasis that the current Yahoo! DMARC mess is unrelated to issues with SPF as defined in either RFC 4408 or 4408bis.

Typical MLM managed lists send messages that pass SPF for the list's domain (which is typically what is found in Mail From).  Conceptually this is somewhat similar to the list adding it's own DKIM signature. Both pass/verify for SPF/DKIM, but neither are aligned to the From, so DMARC calls them a fail.

SPF and transparent forwarding is an issue, but not this one. 

Scott K


_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822