Re: [Bimi] Guidance Document - Refactor input

"Brotman, Alex" <Alex_Brotman@comcast.com> Fri, 09 April 2021 00:36 UTC

Return-Path: <Alex_Brotman@comcast.com>
X-Original-To: bimi@ietfa.amsl.com
Delivered-To: bimi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 547683A239B for <bimi@ietfa.amsl.com>; Thu, 8 Apr 2021 17:36:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=comcast.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YfOWpP9oOqfQ for <bimi@ietfa.amsl.com>; Thu, 8 Apr 2021 17:36:14 -0700 (PDT)
Received: from mx0a-00143702.pphosted.com (mx0a-00143702.pphosted.com [148.163.145.77]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7AC303A239D for <bimi@ietf.org>; Thu, 8 Apr 2021 17:36:14 -0700 (PDT)
Received: from pps.filterd (m0156893.ppops.net [127.0.0.1]) by mx0a-00143702.pphosted.com (8.16.0.43/8.16.0.43) with SMTP id 1390QEVW023014; Thu, 8 Apr 2021 20:36:13 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comcast.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=20190412; bh=1CRR2KtTdfmcAR+1vnJQxkxdSXCBvhfbqBNegEqeK0Y=; b=AZr+HqD1s191JlaAeRHVdCKFIyV8XKMht9YVEvlZ0ZSWvYDHdAlR7SyfBiDCg+yvMaoa shwtWqxYP6p6GTJACAv2XIha0JQjL9YUgAkIpYPxFFE36u9siEUKgbyNDuIZV0QaW2DE JMArBMOXSiw3UJlGTS8Yg3YqaJRJyPp433QqRFS3uK5i3NbGSZEFpbwo6NSHd5IErMvc 85OF2De3690YxPgAZgBJTJ60wiZYKa2SrXSvJKlzp+SAWGDCaavfRj6Ahv4TSACF2v/D TPcadJ9krQnCRFUPSR3IEGPFhF+5JMQ3Xb4CprVEck6bB9j0Fs5sEencgrmEIFuPdG4d Og==
Received: from pacdcex50.cable.comcast.com (dlppfpt-wc-1p.slb.comcast.com [96.99.226.136]) by mx0a-00143702.pphosted.com with ESMTP id 37sk0kag1n-2 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Thu, 08 Apr 2021 20:36:13 -0400
Received: from PACDCEX49.cable.comcast.com (24.40.2.148) by PACDCEX50.cable.comcast.com (24.40.2.149) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 8 Apr 2021 20:36:10 -0400
Received: from PACDCEXEDGE01.cable.comcast.com (76.96.78.71) by PACDCEX49.cable.comcast.com (24.40.2.148) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Thu, 8 Apr 2021 20:36:10 -0400
Received: from NAM12-MW2-obe.outbound.protection.outlook.com (104.47.66.40) by webmail.comcast.com (76.96.78.71) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 8 Apr 2021 20:35:40 -0400
Received: from MN2PR11MB4351.namprd11.prod.outlook.com (2603:10b6:208:193::31) by MN2PR11MB4463.namprd11.prod.outlook.com (2603:10b6:208:190::25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3999.32; Fri, 9 Apr 2021 00:35:38 +0000
Received: from MN2PR11MB4351.namprd11.prod.outlook.com ([fe80::1dc0:e771:def5:fde8]) by MN2PR11MB4351.namprd11.prod.outlook.com ([fe80::1dc0:e771:def5:fde8%3]) with mapi id 15.20.4020.017; Fri, 9 Apr 2021 00:35:38 +0000
From: "Brotman, Alex" <Alex_Brotman@comcast.com>
To: Zack Aab <zack@trendlineinteractive.com>
CC: "BIMI (IETF) (bimi@ietf.org)" <bimi@ietf.org>
Thread-Topic: [Bimi] Guidance Document - Refactor input
Thread-Index: Adcr8F041vqA26wUTEisW5zvmDHd0gAptcUAABAcH9k=
Date: Fri, 09 Apr 2021 00:35:38 +0000
Message-ID: <MN2PR11MB4351959B6D5C3AFB22E91059F7739@MN2PR11MB4351.namprd11.prod.outlook.com>
References: <MN2PR11MB4351A92BB103B9EF83A5122EF7759@MN2PR11MB4351.namprd11.prod.outlook.com>, <CAFOdbD1URXUyEOTt8286daQEHw_XAQ70F-m3mPJhjmfjrC0wQw@mail.gmail.com>
In-Reply-To: <CAFOdbD1URXUyEOTt8286daQEHw_XAQ70F-m3mPJhjmfjrC0wQw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: trendlineinteractive.com; dkim=none (message not signed) header.d=none;trendlineinteractive.com; dmarc=none action=none header.from=comcast.com;
x-originating-ip: [2601:43:101:380::c7df]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: a348985a-b201-4a76-eb67-08d8faef65e9
x-ms-traffictypediagnostic: MN2PR11MB4463:
x-microsoft-antispam-prvs: <MN2PR11MB446326B4CF6D4C06864CD403F7739@MN2PR11MB4463.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: SxLHB3t2cQ/YSl6D7Scw4ApQ02e28XPDpzRVEEgulrr3GawnsUofiKSEcxsv9LIx9qvK0IMzSctNYe2R9kkrm321cPVqbqV8pkxf+QrokHvp5g4jQAEEH+ohS1G5ZYPa2l6X7daDosuLW/SNm0AOJ/bBnZCgn8kRmXnLoVekFJxEUYK8ugDGn6yOFQwP+BC2xTlV43SUJoUJTMQjxay/Jg1lC/28y8z46RjlsHho2y48ViAiqBZFrdOBio0jGcGvUOqE6uBtopZtV9KdIm21eOss5RL5f2OpNR37ODc8QOFPfi7L5ToBO+vKrhspmQwQtBvdQAisM+EPjsrg6E/kmiJy6Nw4iN5y+Hs8BSsIwAwS3mcLTVRpSvk1tGZds/chGJ1Zul4Cw1LPmMVu2Ymjc/e7rEP6tEqfW0KpOlexylIyBBbOjtNaKIGMBdEhZiQo+2kbqskoEYLDnpMjKtcQdV2MBACKQHt+BZz3HZkesSoirRa2KoUCh3F0tZInKMY8AIk2tpp+jDvPSWOffqLfX6RPj6+E6/D/tllYWb8aquqnHhLpngSIwifc5f4oojrYehHsLHOLsicXB/Hb9UmXTMntc5PWXsJ3pUsoP+bQljnTgtFMMQRd4HWhMr/JL5zsBp7+K5IXhTU58shbFXlYroYCwEMjhY9nQ12c30b0Fnla6QU6bR4a5FCi/c2dfqgQiPfKwL8FU5OsoaxuRzAK1hP6osPJ/whMkNmD2/xb0Y8=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB4351.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(396003)(39860400002)(366004)(376002)(136003)(346002)(66476007)(71200400001)(76116006)(66946007)(6506007)(66556008)(53546011)(64756008)(186003)(66446008)(966005)(478600001)(2906002)(38100700001)(86362001)(7696005)(6916009)(5660300002)(316002)(8936002)(4326008)(8676002)(33656002)(52536014)(83380400001)(55016002)(9686003); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: y+/XS6C2JArwHs4uD9+5KXqlhimXm/kLjTwDMYCO3IoU/odhFJCjCC17gKX0kP4Ked3/A8oV5X9sxaHw3pokWQkwnRu2BvuGrYeBVpup0xo7Pv9qkxo0aTdU2WSM1H7Zk6/LvtSnfpCIPm1Kf7zmZcpUiK8hCBfl0SpB+s49CwQ8YYx1U6cIb9ihykpmxvEJ82JXRtSgBYqqd4enzOBFXjvMwmSu3h6fnFIktsDBVNSsyyxWt11h0P8G07ZEvFKshwclSdb9dE805djTj0zaBFq1L+IGnuxrzlOoiu4vZBpMKe9iH77oBPi4jV60nVlJW+f7glCllFXZTOgxt67hX3LNaMuj7yuiwGJSBgEP7hRzw+0c64AfSZWrJF+72fLqdFSETH7rVmA1FrouS5E2NurlQWCcE9TdoJM8KBcLYfeXBV+03muwFCoS17b3ViThGla8d7BjQ6jFh5smssvaH57xq6A7gb/++wpKWsDsukK/oGXJW+l4NkhwEwjC3jyLv3iLT82pqvpmb23SiBIFARng9B/40Oe8Ddba7cbjqMiULHKT26S1Zb0MsmtA7eiKpytFNAbNpLYNAs3UJOxpGGRlGB/KP/oOiNU4yDm76OBWyYOYRKDgvKdLAVWdy7a7oN8l8VMnKS26huUsS8XTMQoC/DamavYSi64PEtFWfJ64Ru6g0oZM8jT3AjOTUZ9Oh3Yd60PaBF6RWBN4OyUUFRZaLG+i+E7bjmMbsixM09JAylytyyoGygxjf1puvsl6xC7sENKBNgLbfy/16nV4dM95x+v3MOGPqssD8AbGk9CoY6bmL6AuVQ19U2TI3AkCUFuEVHY1Rfjjlxy/RgGu4Hy5+1QI9ZmoZr4XzPZk9XxK0JFF9zn9N/k1CdJTE/dUdByAn4C4skyXoW3/s4r7w5J9irCISkKcxjwsdiQSenY8/RWmjy/M7PDWfdYzJ+rXp89TvZtbJ/fe2Qsq2tCkSTxPtNxLKmJXJXCjJMe6DOeO4Sw4edJo+jXyV4jM5C9m12uuLmgnSqNqpOpVgrKAuaejxbpx+JJrrVa6DRLNF5Fl8srwkDYkgpTQW2yV9WxaeX5Zhg/Jdh+pTidmHuCVEnLKCMOyemMdtQY6yYkDabVamaL4WD0vrdWe3i62Zl+0px+hdiujnG6lYV2alYDYnqfpoMN++Y7IS/vnwSALGjuP805An4PxeAp1PR+4hPOb80sevmiKtZowgvXYZUAGUiIYJ+HgSI5CJkxoT5nwER30osKFdbvpsIIfQDW42dEgy8SjWdRmh/KauHI5bD4zTUUc0d+XTgrgOfwkfT623HFQDeaOjwDNUETnK4upCzqzGxs9m+UxkBD+6aCcoPs6mQ==
x-ms-exchange-transport-forked: True
arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=aFH+Y7P3C2IAF+1FQ/gAQlmfi40w9NIHC4gFDgnwEaN4YN9JO5JHMPbA+14UmxXWP7NC3+6AlQRxUBJHbEcLmhhf7MQNU/w7s/dNhI6WAGT4cLNj4e4j2+piWV6MVeXgJ9hfauPQl5Ho5LMjxDyi0ea0xgO3ysqnQOeEmLqW4dqpUBagK5coB3ctFiV2FMmw2u9su06LA7nNXdnXGsElljgAULiPP0lLY70w24pSVSt9ZLCpaJgSGamToSz6fHQ9dKNRQlmw78lUm8R+mopFZlS3Pjr7FPT0rQmvkPeo7DQlYsOcbcV1wlezjWvXyl0H9LSVk44j9IyMbsPpzBGdRw==
arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ericKL8JQN4cu6UxRdF8VgAbsPHHgz1zmY978hwbNfc=; b=OJFzRagaU94Uewrg0JSd6BbIHYa+/zOOp1niJ4NPrzmwnnaWNUi25HvHsS5OTZGZN666IrMdAu0UpReCHfLkxitoseahn82QGVTT5DOaH7l+6E+EcZTytmP//PU+Sn8z328Pad9GtiLkkqIykyvcxjnUm16CVUZKRtAWOjpndjO2T3qYOf9EMlkHu7+S+0+juHfyvKb/bI0fVr4ZnExLlkQ5m4fFp2PK2AHiVmIQXUAH+7rUrc7U5jhRFKJJldHb8GV25obLn3daoeXAiriI5GPCu0LtLbk/3eGdAWVruROYVF0jTgHJGrsS48oBcNVMH0vBDRq68Ge8w+P+edl3AA==
arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=comcast.com; dmarc=pass action=none header.from=comcast.com; dkim=pass header.d=comcast.com; arc=none
x-ms-exchange-crosstenant-authas: Internal
x-ms-exchange-crosstenant-authsource: MN2PR11MB4351.namprd11.prod.outlook.com
x-ms-exchange-crosstenant-network-message-id: a348985a-b201-4a76-eb67-08d8faef65e9
x-ms-exchange-crosstenant-originalarrivaltime: 09 Apr 2021 00:35:38.5682 (UTC)
x-ms-exchange-crosstenant-fromentityheader: Hosted
x-ms-exchange-crosstenant-id: 906aefe9-76a7-4f65-b82d-5ec20775d5aa
x-ms-exchange-crosstenant-mailboxtype: HOSTED
x-ms-exchange-crosstenant-userprincipalname: oEJotqt8SDgrsk6ugkwTpcddWyc2nKq7p+tuDci6WW6rNIzEnQYX8tdE3BqTzYfrFO+p15HmD0dKUKSKm/Jq3ZSx/XRxM9zldZmpg8RwZ44=
x-ms-exchange-transport-crosstenantheadersstamped: MN2PR11MB4463
x-originatororg: comcast.com
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-CFilter-Loop: Forward AAETWB
X-Proofpoint-GUID: nD9_P71RbLL5XuIoTXsRMM4zy-BFrHXk
X-Proofpoint-ORIG-GUID: nD9_P71RbLL5XuIoTXsRMM4zy-BFrHXk
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.391, 18.0.761 definitions=2021-04-08_12:2021-04-08, 2021-04-08 signatures=0
X-Proofpoint-Spam-Reason: safe
Archived-At: <https://mailarchive.ietf.org/arch/msg/bimi/ff-MJLJSvwTe2T3hg_TEhM61UP8>
Subject: Re: [Bimi] Guidance Document - Refactor input
X-BeenThere: bimi@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Brand Indicators for Message Identification <bimi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/bimi>, <mailto:bimi-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bimi/>
List-Post: <mailto:bimi@ietf.org>
List-Help: <mailto:bimi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/bimi>, <mailto:bimi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Apr 2021 00:36:19 -0000

That's reasonable to have somewhere.  You're suggesting something akin to a flowchart, correct?  Would you be looking for this to include configuration from the brand side of things?

--
Alex Brotman
Sr. Engineer, Anti-Abuse
Comcast
x5364

________________________________________
From: Zack Aab <zack@trendlineinteractive.com>
Sent: Thursday, April 8, 2021 12:49 PM
To: Brotman, Alex
Cc: BIMI (IETF) (bimi@ietf.org)
Subject: Re: [Bimi] Guidance Document - Refactor input

$0.02 worth:
The info is already there in various places, but since BIMI might require some organizations to add brand new code, an explicit "example mail agent workflows" section that is simply all of the BIMI-related actions (what action, not how) taken by the MTA, MUA, etc., would probably be helpful.
I also think something along the lines of the "minimum implementations" section in the DMARC RFC https://tools.ietf.org/html/rfc7489#section-8<https://urldefense.com/v3/__https://tools.ietf.org/html/rfc7489*section-8__;Iw!!CQl3mcHX2A!X3UO3VkKSbc6MN2ESm5qWFWS7YvvuDK8-92NiYNMCl72P3FkuRQSG5qLcA3aL5hmV7eX$> would be valuable.

Zack Aab (He/Him)
Senior Consultant, Trendline Interactive
O +1 (512) 717-4097<tel:+15127174097> | C +1 (404) 317-6729<tel:+14043176729> | W trendlinei.com<https://urldefense.com/v3/__https://www.trendlineinteractive.com/__;!!CQl3mcHX2A!X3UO3VkKSbc6MN2ESm5qWFWS7YvvuDK8-92NiYNMCl72P3FkuRQSG5qLcA3aL_o0FRg0$>


On Wed, Apr 7, 2021 at 4:56 PM Brotman, Alex <Alex_Brotman=40comcast.com@dmarc.ietf.org<mailto:40comcast.com@dmarc.ietf.org>> wrote:
Hello folks,

We're looking to refactor the existing Receiver Guidance document to be more general purpose.  We thought we'd reach out to others on the list to see what areas they believe we should touch on.  We wanted the new iteration of the document to be something that can be referenced by all parties involved with BIMI such as Receivers, Senders, ESPs, Logo Designers, MUA authors, and so on.   We do intend to move over some of the existing content, so those have been included below.

We started a rough outline of sections to cover, and we'd welcome feedback.  Thanks for any input you could provide.


# Abstract
# Introduction
# Goals for BIMI
# Should you implement BIMI?
## As a Receivers
## As a Brands
# Terms
# Sections covered below (definitions of each group)
## Receivers
### Site implementation
### Validation of a BIMI message
#### Additional requirements
### Retrieval of image files
#### TTL for cached images
### VMC Root of Trust
## Senders/ESPs
### DMARC for Customers
## Brands
### Obtaining a VMC
### Logo Hosting Considerations
#### CDN Considerations
## MVAs
## Logo Designers
### Known Issues
### Adherence to SVG P/S
### Tools and Caveats
## MUA Creators
### Image Dispay
# Privacy Concerns
# FAQ


--
Alex Brotman
Sr. Engineer, Anti-Abuse & Messaging Policy
Comcast

--
bimi mailing list
bimi@ietf.org<mailto:bimi@ietf.org>
https://www.ietf.org/mailman/listinfo/bimi<https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/bimi__;!!CQl3mcHX2A!X3UO3VkKSbc6MN2ESm5qWFWS7YvvuDK8-92NiYNMCl72P3FkuRQSG5qLcA3aL0Fw-o8d$>