Re: DMARC?
Scott Kitterman <[email protected]> Fri, 17 Aug 2012 02:31:42 -0400
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <5021703.MzElIc646q@scott-latitude-e6320> |
On Thursday, August 16, 2012 06:52:25 PM Michael Deutschmann wrote: > On Sun, 12 Aug 2012, Tim Draegen wrote: > > DMARC has already shown great utility in the real world, so it's odd to > > read things like "DMARC moves in precisely the wrong direction" and "I can > > see the rationale for ADSP and DMARC's insanity". > > I was specific as to what I consider insane - the targetting criteria. > You cannot select anything for rejection or quarantine without also > selecting all legitimate mailing list posts for the same treatment. This > was broken in ADSP and DMARC has done nothing to fix it. > > Sure, an *option* to say "No one at this domain posts to a > signature-breaking mailing list" would be useful to the rare sender > domain that can make the claim, ensuring that even phish dolled up to > look (to the filters) like something the recipient subscribed to would be > reliably blocked. > > But making it a requirement ensures that most domains can never deploy a > non-null DMARC policy. That then means there is little incentive to > deploy DMARC at the receiverside. > > In contrast, the *opposite* way to "combine SPF and DKIM" would have been > quite helpful. That is, provide a way for a domain to signal that > messages bearing its Return-path: always have a corresponding DKIM > signature, while saying nothing about messages with its From: but a third > party's Return-path:. This would have no SPF forwarding problem and no > DKIM mailing list problem. They've got a target audience and most domains aren't in it. I think that's fine as long as they are clear about it. I've published DMARC records with a policy of none for the feedback reports. Those I think are potentially useful for everyone. They are a great part of the answer to "how do I check if I got my SPF records right". That's been a tough one for a long time. Scott K