Re: DMARC?

Michael Deutschmann <[email protected]> Thu, 16 Aug 2012 18:52:25 -0700 (PDT)
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <%[email protected]>
On Sun, 12 Aug 2012, Tim Draegen wrote:
> DMARC has already shown great utility in the real world, so it's odd to
> read things like "DMARC moves in precisely the wrong direction" and "I can
> see the rationale for ADSP and DMARC's insanity".

I was specific as to what I consider insane - the targetting criteria.
You cannot select anything for rejection or quarantine without also
selecting all legitimate mailing list posts for the same treatment.  This
was broken in ADSP and DMARC has done nothing to fix it.

Sure, an *option* to say "No one at this domain posts to a
signature-breaking mailing list" would be useful to the rare sender
domain that can make the claim, ensuring that even phish dolled up to
look (to the filters) like something the recipient subscribed to would be
reliably blocked.

But making it a requirement ensures that most domains can never deploy a
non-null DMARC policy.  That then means there is little incentive to
deploy DMARC at the receiverside.

In contrast, the *opposite* way to "combine SPF and DKIM" would have been
quite helpful.  That is, provide a way for a domain to signal that
messages bearing its Return-path: always have a corresponding DKIM
signature, while saying nothing about messages with its From: but a third
party's Return-path:.  This would have no SPF forwarding problem and no
DKIM mailing list problem.

---- Michael Deutschmann <[email protected]>