Re: DMARC?
Michael Deutschmann <[email protected]> Thu, 16 Aug 2012 18:52:25 -0700 (PDT)
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <%[email protected]> |
On Sun, 12 Aug 2012, Tim Draegen wrote: > DMARC has already shown great utility in the real world, so it's odd to > read things like "DMARC moves in precisely the wrong direction" and "I can > see the rationale for ADSP and DMARC's insanity". I was specific as to what I consider insane - the targetting criteria. You cannot select anything for rejection or quarantine without also selecting all legitimate mailing list posts for the same treatment. This was broken in ADSP and DMARC has done nothing to fix it. Sure, an *option* to say "No one at this domain posts to a signature-breaking mailing list" would be useful to the rare sender domain that can make the claim, ensuring that even phish dolled up to look (to the filters) like something the recipient subscribed to would be reliably blocked. But making it a requirement ensures that most domains can never deploy a non-null DMARC policy. That then means there is little incentive to deploy DMARC at the receiverside. In contrast, the *opposite* way to "combine SPF and DKIM" would have been quite helpful. That is, provide a way for a domain to signal that messages bearing its Return-path: always have a corresponding DKIM signature, while saying nothing about messages with its From: but a third party's Return-path:. This would have no SPF forwarding problem and no DKIM mailing list problem. ---- Michael Deutschmann <[email protected]>