Re: DMARC?

Scott Kitterman <[email protected]> Fri, 17 Aug 2012 02:31:42 -0400
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <5021703.MzElIc646q@scott-latitude-e6320>
On Thursday, August 16, 2012 06:52:25 PM Michael Deutschmann wrote:
> On Sun, 12 Aug 2012, Tim Draegen wrote:
> > DMARC has already shown great utility in the real world, so it's odd to
> > read things like "DMARC moves in precisely the wrong direction" and "I can
> > see the rationale for ADSP and DMARC's insanity".
> 
> I was specific as to what I consider insane - the targetting criteria.
> You cannot select anything for rejection or quarantine without also
> selecting all legitimate mailing list posts for the same treatment.  This
> was broken in ADSP and DMARC has done nothing to fix it.
> 
> Sure, an *option* to say "No one at this domain posts to a
> signature-breaking mailing list" would be useful to the rare sender
> domain that can make the claim, ensuring that even phish dolled up to
> look (to the filters) like something the recipient subscribed to would be
> reliably blocked.
> 
> But making it a requirement ensures that most domains can never deploy a
> non-null DMARC policy.  That then means there is little incentive to
> deploy DMARC at the receiverside.
> 
> In contrast, the *opposite* way to "combine SPF and DKIM" would have been
> quite helpful.  That is, provide a way for a domain to signal that
> messages bearing its Return-path: always have a corresponding DKIM
> signature, while saying nothing about messages with its From: but a third
> party's Return-path:.  This would have no SPF forwarding problem and no
> DKIM mailing list problem.

They've got a target audience and most domains aren't in it.  I think that's 
fine as long as they are clear about it.

I've published DMARC records with a policy of none for the feedback reports.  
Those I think are potentially useful for everyone.  They are a great part of 
the answer to "how do I check if I got my SPF records right".  That's been a 
tough one for a long time.

Scott K