Re: DKIM and DMARC, Email explained from first principles
Sam Varshavchik <[email protected]>
| Newsgroups | gmane.ietf.smtp |
|---|---|
| Message-ID | <[email protected]> |
Dave Crocker writes: > Actually, no, that's not what I said. Bad actors are always the first to > adopt the newest anti-spam technologies, to abuse those unfortunates who > interpret DKIM the way you described. > > DKIM establishes a clean (noise-free) channel from the signer, which means > that any assessment about them really is about them. If they are bad > actors, that is a lot easier to assess, as is if they are good actors. Ah, but the first paragraph's the rub. That's why I saw DKIM-Signature: as a spam indicator: the bad actors' initial take-up of DKIM-Signature: was quite noticable. That was definitely true at one point. Based on today's numbers that I looked at the mainstream adoption of DKIM sadly diluted its early value as a spam indicator, ironically. >> But nearly all other spam, the kind that I do have a major problem with, the >> specific type that I'm bitching about, nearly all of it carries a DKIM- >> Siganture: field. I only found very, very few exceptions to that. > > For those assessed as bad actors, was any of their mail mixed in with mail > from a different signer who was assessed to be a good actor? My sample wasn't large enough for that. I have no recollection of seeing this; except I have a dim recollection of receiving something non-spam from Sendgrid a very, very long time ago, before I wrote them off as damaged goods. Interestingly enough, while researching this response, I found a copy of a sendgrid-sourced spam from December 2020, from a previously unknown (to me) IP address range (it was spamming an SMS-spam service). It did not have a DKIM/DMARC signature of any kind. Nothing from Sendgrid since then until today, when Sendgrid attempted to spam one of my Sourceforge mailing lists, with a monstrous DKIM-signed spam in Spanish. So, looks like Sedngrid is >> Now, to John's point, that DKIM alone is not indicative of reputation, that >> it only serves to ascertain identity, and with that out of the way you can >> now evaluate the proven identity's reputation. Well, the problem with that >> is twofold: >> >> 1) There are no known (at least to me) established reputation providers. And >> even if there are some that claim to be, history teaches that they don't >> really accomplish much. > > Gosh, you mean that each evaluator needs to formulate their own criteria, > about a complex, fuzzy topic? Yup! > >> >> 2) So you're left with building and maintaining your own reputation database. >> >> That seems like a lot of work to me. > > It is. Sad reality. Lot of criminals on the streets make safe navigation > challenging. Most people need to outsource their safety efforts. You can't really have both. Either you "formulate your own criteria", or you'll outsource your spam filtering. _______________________________________________ ietf-smtp mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-smtp
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEMWrVnbBKLOeG9ifkazpiviedvyUFAmCtrmoACgkQazpivied vyVQXw//ZNsg+QIAlmxBynYljBwhVos7EmyOqdPyNY/uMhIf2V27nuH2XwwcmJD2 y0Z+7l8gVXdqlt3emDpZ/ZSs6jrW317y2ISREY5l5lSg0wKfVf2MUNu8wIuYga6y ZtyPeYoLCCfuNxiZnNtIV42YhLsFt0sUvQtdRtGu4jngN0DwJDs/NlMoAS56ClBc 3S2gmt9gwNZseWmI0JLQNZwGVATZXSmCq0MjG3Fej48PCoJ7MVQFV9JArxWtO/FI j6SjEnO7DREghxZhQu7urSIfZVU0k6dep6fB7NXoZD5y2TlW+ptl3QZwrfjmZ/bx xXuuYhRPvHtT1FRSYaihc4rUs2X9EaZe//4cDz9d7yCkkHI7HAjhjjVh2Ad6Kj44 pmQgr1ts7mf3TOrYpz84k1qY/EnmIv7xe/pswgzRbfvonWg2PKR817vGspOukbDA jNKjr4LDF+H0jzTEyPNa+y96DxH5fEMormQKZBSTsr4RN9VTWILBs9IVmZ4JCetG n1iVu7K0AP1xDwoEblhJcRRyzjxp7Zq5Xx08MJH10V4U4TYX2aX6qb5YCnRD4ck9 TZ1WTK8PjzV0ZjY74X0rUA6wfz8mGqaS7K85SOG61QzZwxwVx28pVfobMWt9F6TR ttauegLc/De9xGV3fdB8JXh/U6HQiIxgkxA6LSgbMqMmYYqR/7I= =SCQp -----END PGP SIGNATURE-----