Re: DMARC?

Scott Kitterman <[email protected]> Tue, 07 Aug 2012 13:20:08 -0400
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <4468409.RaseGXI6iX@scott-latitude-e6320>
On Tuesday, August 07, 2012 01:05:10 PM Dotzero wrote:
> On Tue, Aug 7, 2012 at 12:50 PM, Don Lee
> 
> <[email protected]> wrote:
> > Anyone know about this:
> > 
> > http://www.dmarc.org/
> > 
> > I've spent about 10 minutes looking into it, and it looks like a
> > worthwhile
> > effort.  Other opinions?
> > 
> > -dgl-
> 
> I'm one of the participants in dmarc.org (I beleive there are some
> others who are lurking here as well. The effort basically came out of
> the experience that a handful of senders and large mailbox providers
> has doing something similar through private channels. The policy
> assertion piece may not be for all senders but the reporting part
> allows visiblity into auth failures where there didn't use to be any
> visibility. For validators/receivers it is useful but not as usefulas
> when there is greater adoption by senders. By combining the use of SPF
> and DKIM you reduce false positives.

I agree, with the slight caveat that the way the DMARC spec is written now, it 
says that a DMARC policy record should override other policies, so if I 
publish a DMARC record to get feedback, I'm at the same time telling receivers 
not to take a policy action based on SPF fail.  This is a problem that I think 
will be addressed, but it hasn't been yet.

Scott K