Re: DMARC Extension for 3rd party Signers

Hector Santos <[email protected]> Sun, 20 Apr 2014 01:51:28 -0400
Newsgroups gmane.ietf.rfc822
Organization Santronics Software, Inc.
Message-ID <[email protected]>
On 4/20/2014 1:14 AM, Scott Kitterman wrote:
> On Sunday, April 20, 2014 00:59:09 Hector Santos wrote:
>> On 4/20/2014 12:17 AM, Scott Kitterman wrote:
>>>> Where is the alignment requirement description for when only p=reject
>>>> is used?
>>>
>>> See section 3.1.4 of the current DMARC draft.
>>
>> Got it. I see the problem.  DMARC by definition requires alignment for
>> matching domains. An adkim=s (strict) is an exact match and adkim=r
>> (relaxed) means sub-domains are allowed.
>>
>>   From what I see, there is no 3rd party allowance and the only things
>> that saves you is p=none or p=quarantine.
>
> Yes.  As currently defined, p=reject is only suitable for some classes of
> domains and the current mess is because yahoo.com isn't in one of those
> classes.

I don't agree that yahoo.com isn't one and neither does Yahoo.   Yes, 
it is a long time polluted and publicly used email domain but it was 
only because of a lack of method to check all the bad stuff. Millions 
of other domains are in the same boat, such as my santronics.com corp 
domain.  Its very "polluted."

 From my standpoint, all domains must be treated the same with any 
protocol, and the solution is not to think yahoo or any other domain 
can not be an user of the protocol.   That was the mistake belief with 
ADSP, trying to define "classes" of domains and exclude other 
"classes" for strong policy considerations and it took YAHOO to do it 
via DMARC to show that.  Their domain was way too polluted.  It was 
time to do this.  I expect an avalanche of private and public domains 
increasing their security value using DKIM + POLICY, in this case with 
DMARC.

But it still needs 3rd party "classes" of policies semantics to make 
it work right across the board.  We are going to go right back to the 
ultimate consensus of the main problems with 3rd party controls, 
namely scalability and manageability.   We need to see if ATPS can 
work, at least for a majority (80%) of the domains.  Yahoo said 
something about 30,000 mailing list and their yahoo.com users??  Well, 
can they manage 30,000 ATPS records?  Can DNS?

-- 
HLS


_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822