Re: DMARC?
Don Lee <[email protected]> Tue, 7 Aug 2012 12:46:21 -0500
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <p06240803cc4704241e90@[72.1.155.212]> |
>On Tuesday, August 07, 2012 01:05:10 PM Dotzero wrote: >> On Tue, Aug 7, 2012 at 12:50 PM, Don Lee >> >> <[email protected]> wrote: >> > Anyone know about this: >> > >> > http://www.dmarc.org/ >> > >> > I've spent about 10 minutes looking into it, and it looks like a >> > worthwhile >> > effort. Other opinions? >> > >> > -dgl- >> >> I'm one of the participants in dmarc.org (I beleive there are some >> others who are lurking here as well. The effort basically came out of >> the experience that a handful of senders and large mailbox providers >> has doing something similar through private channels. The policy >> assertion piece may not be for all senders but the reporting part >> allows visiblity into auth failures where there didn't use to be any >> visibility. For validators/receivers it is useful but not as usefulas >> when there is greater adoption by senders. By combining the use of SPF >> and DKIM you reduce false positives. > >I agree, with the slight caveat that the way the DMARC spec is written now, it >says that a DMARC policy record should override other policies, so if I >publish a DMARC record to get feedback, I'm at the same time telling receivers >not to take a policy action based on SPF fail. This is a problem that I think >will be addressed, but it hasn't been yet. > >Scott K My brief reading is that it is a complementary, and helpful standard, not one that is generally in conflict with SPF (or DKIM). SPF, DKIM, and other proposals seems to me to have been looking for a "silver bullet" and have turned out to need broader support from various stakeholders. It looks to me like DMARC is part of that helpful, cooperative evolution, and will help everyone adopt and deploy these technologies. -dgl-