Re: DMARC?

Ian Eiloart <[email protected]> Tue, 21 Aug 2012 12:00:49 +0000
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
On 21 Aug 2012, at 04:08, Michael Deutschmann <[email protected]> wrote:

> On Mon, 20 Aug 2012, Ian Eiloart wrote:
>> On 11 Aug 2012, at 20:54, Michael Deutschmann
>> <[email protected]> wrote:
>>> a phisher can freely lie in
>>> *the address shown to an unsuspicious end user*
>> 
>> Actually, there's no such thing for many recipients. Outlook 2011 for
>> OSX (and I think 2010 and earlier for PC), iOS Mail, Yahoo webmail and
>> Hotmail webmail don't display sender email addresses by default. For those
>> webmail clients, a mouseover can reveal the From: header address, but for
>> Outlook and iOS Mail, it's really hard to find the address even when you
>> know how.
> 
> So they only show the display name.
> 
> Well, then the phishers have free reign -- they can evade all technical
> anti-forgery measures by simply not forging.  They just have to use their
> real domain in all headers including From:
> 
> Only a display-name anti-forgery protocol can help, and that is
> problematic.  To their credit, DMARC's specification draft at least
> discusses it, but only to point out they have no idea how to plug the
> hole, and hope someone else will.
> 
> Anyhow, it underscores my point that ADSP/DMARC's obsession with
> protecting only the most visible header (From:) is insane.
> 
> SPF's forwarding problem is annoying, but only indirectly.  I've been
> publishing -all since 2004 and only once encountered a domain bouncing my
> mails and blaming SPF.  It only hurts because my false negative rate is
> boosted by cowards who use ?all unnecessarily.
> 
> But the ADSP/DMARC mailing list problem, which could be trivially avoided
> by joining SPF in protecting the bounce address instead, is fatal.
> 
> ---- Michael Deutschmann <[email protected]>
> 


Well, I think we need to lobby the mail client developers to show the email address, since it's critical. Heck, some don't even show the email address when you reply to the email. It's terrifying!

But, the real responsibility lies with those who (should) have competence - the MTA operator.

What both SPF and DKIM give us are ways of fixing reputation systems to domains or email addresses. And, if mailing lists break DKIM, that doesn't much matter - it's the list's reputation that recipients should care about. They need to add their own DKIM signatures. 

DMARC gives senders feedback about the effects of their publication of SPF and DKIM records. That's useful in itself, and my initial reaction is that we should adopt it.

-- 
Ian Eiloart
Postmaster, University of Sussex
+44 (0) 1273 87-3148