Re: DMARC?

Michael Deutschmann <[email protected]> Sat, 18 Aug 2012 15:29:57 -0700 (PDT)
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <%[email protected]>
On Fri, 17 Aug 2012, Scott Kitterman wrote:
> They've got a target audience and most domains aren't in it.  I think
> that's fine as long as they are clear about it.

The problem with that is that with only phish-target domains deploying it
senderside, there is too little incentive to deploy it receiverside.

Despite the fact that DMARC should have no false positives, it seems
pointless because the expected amount of bad mail it would supress in a
year comes to about zero.  A lot of bad mail is forged, but only actual
phish is forged in the name of a phish-fearing domain.

> I've published DMARC records with a policy of none for the feedback
> reports.

Which still doesn't incentivize anyone to deploy it receiverside.


I notice some people in the DKIM camp seem to think that once their
standards advance far enough, then total receiverside deployment will just
appear by magic.  Although they apparently also think this deployment will
be done by a jerk literal genie who will build the most porous possible
configuration that still complies with the letter of the RFC.

(That's the only way to explain Douglas Otis's panic on the IETF list over
his theoretical "double From:" exploit.)

---- Michael Deutschmann <[email protected]>