Re: DMARC?

Michael Deutschmann <[email protected]> Mon, 20 Aug 2012 20:08:53 -0700 (PDT)
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <%[email protected]>
On Mon, 20 Aug 2012, Ian Eiloart wrote:
> On 11 Aug 2012, at 20:54, Michael Deutschmann
> <[email protected]> wrote:
> >  a phisher can freely lie in
> > *the address shown to an unsuspicious end user*
>
> Actually, there's no such thing for many recipients. Outlook 2011 for
> OSX (and I think 2010 and earlier for PC), iOS Mail, Yahoo webmail and
> Hotmail webmail don't display sender email addresses by default. For those
> webmail clients, a mouseover can reveal the From: header address, but for
> Outlook and iOS Mail, it's really hard to find the address even when you
> know how.

So they only show the display name.

Well, then the phishers have free reign -- they can evade all technical
anti-forgery measures by simply not forging.  They just have to use their
real domain in all headers including From:

Only a display-name anti-forgery protocol can help, and that is
problematic.  To their credit, DMARC's specification draft at least
discusses it, but only to point out they have no idea how to plug the
hole, and hope someone else will.

Anyhow, it underscores my point that ADSP/DMARC's obsession with
protecting only the most visible header (From:) is insane.

SPF's forwarding problem is annoying, but only indirectly.  I've been
publishing -all since 2004 and only once encountered a domain bouncing my
mails and blaming SPF.  It only hurts because my false negative rate is
boosted by cowards who use ?all unnecessarily.

But the ADSP/DMARC mailing list problem, which could be trivially avoided
by joining SPF in protecting the bounce address instead, is fatal.

---- Michael Deutschmann <[email protected]>