Re: DMARC?
Tim Draegen <[email protected]> Sun, 12 Aug 2012 11:02:48 -0400
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <[email protected]> |
On Aug 11, 2012, at 3:54 PM, Michael Deutschmann <[email protected]> wrote: > On Tue, 7 Aug 2012, Don Lee wrote: >> Anyone know about this: >> >> http://www.dmarc.org/ > > I recently perused it. I'd have to do a more careful read of the draft > before I do anything to my DNS in response, but from what I can tell there > seems no point. DMARC moves in precisely the wrong direction. Cliff notes version: - Domain Owners get new visibility into which servers on the internet are emitting email on behalf of their domains. Even if you never intend to put quarantine or reject policies into place, the feedback piece alone is incredibly valuable. - The above mentioned feedback allows complex organizations to accurately deploy SPF and DKIM across their email streams. Email receivers need this accuracy or else policies cannot be safely enforced. - DMARC is aimed at email streams that are highly phished. If you're a large financial organization and you're under attack, DMARC is a viable way to create email streams that are resilient to phishing attacks. - Furthermore, receivers want to move to a model of being able to positively identify legitimate email instead of relying on the dominant "remove bad stuff" model. Doing so allows receivers to process and render authenticated email in new ways. DMARC has already shown great utility in the real world, so it's odd to read things like "DMARC moves in precisely the wrong direction" and "I can see the rationale for ADSP and DMARC's insanity". I recommend reading through some of the introductory materials on dmarc.org; you'll find descriptions of the problems DMARC is attempting to solve, along with links to even more resources. HTH, =- Tim