[dmarc-ietf] Tree Jump method - reporting targeting

Douglas Foster <dougfoster.emailstandards@gmail.com> Thu, 31 March 2022 11:14 UTC

Return-Path: <dougfoster.emailstandards@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 495833A1198 for <dmarc@ietfa.amsl.com>; Thu, 31 Mar 2022 04:14:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.108
X-Spam-Level:
X-Spam-Status: No, score=-7.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xiyQGsfOc2X4 for <dmarc@ietfa.amsl.com>; Thu, 31 Mar 2022 04:14:09 -0700 (PDT)
Received: from mail-oa1-x2d.google.com (mail-oa1-x2d.google.com [IPv6:2001:4860:4864:20::2d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EEE7E3A003F for <dmarc@ietf.org>; Thu, 31 Mar 2022 04:14:08 -0700 (PDT)
Received: by mail-oa1-x2d.google.com with SMTP id 586e51a60fabf-dacc470e03so24982689fac.5 for <dmarc@ietf.org>; Thu, 31 Mar 2022 04:14:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=mime-version:from:date:message-id:subject:to; bh=/enp3Ug2hWOP3uJIzBPTcj5wfv5WPWFMnl4TNIFYbfU=; b=Ouwr5OLZLCEXlSw7co8qU6M6b+ft0Ts79RmeCaGAlRrrX1+m+WjZ8LfVJ4Q3EoCCw3 1McdpapLa4ly56zj52mHFTaN9IUDELwvP+RgJ0HdNsY8P5ZsXBSNSjgt1q5ZzK/LcjFL qRtKR22GE9JSeJkpqMeBrblgx86mo8UP56pgliqOdXtHYZJiL0i+SMVzWIuekaUw23Eq 5BEaDM+yS0IAouX7vpoAffjs1Pg4tbYC+vs0UaWn86AB2TNNiFeLun9c1/16ssoTk8YD BHPSNaZYANIFlFlHEhlx6yaVMXflg/89oRkj5ebp5s8xFbi5y1x6vMLobSkktYLabdPu r3HA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=/enp3Ug2hWOP3uJIzBPTcj5wfv5WPWFMnl4TNIFYbfU=; b=hW2CK+Ct3UbooySdqps5kY/szp/+96D8sEReEZPPb+io3IkTE76w6Sy+3eSUHjeHmu MX7VxvFXRYHSV5t9mOuYrkSF9GLqHLmbdbIDrGPTpCD7syzbgKu/Phr23/efYOhpdvPA 6R3Zv8k+8VEcVWGrgm7/KUUd87hO1OY27b2Q9HAbqVkZqRCnm08jgTG1xBhY3L6qnshh hYrlx0ZTW3xYPdZJgypCFsgJYALaBokE/ZlvOhD0Cu8fadtj/o7hTgmYCB1Y+Q80KHcG 55/rIvpoYQL8JCswDt3na+Mn9B1zhm0QW77//WF5/pKB4yF7Uytq9z7CGSujUMr6C/MQ CHrQ==
X-Gm-Message-State: AOAM532NPXuConHNB3hiANDgRrLMeZ22MrNdSZ7XDjCehCFSIrAlFuWN tXrRHABf3+5l4ix/ucKoIVdD3y0LvgRqogu0oD6Ckvdk
X-Google-Smtp-Source: ABdhPJwfzULaqtv6Iv6Xpv9cGEdriCCC6Bue8Ba6vIS3TT8duIXMCOaerIu8lrBgfCU8daRTxp2APxLMFZa4xW215MM=
X-Received: by 2002:a05:6870:4252:b0:de:8b7a:2be8 with SMTP id v18-20020a056870425200b000de8b7a2be8mr2430978oac.58.1648725247167; Thu, 31 Mar 2022 04:14:07 -0700 (PDT)
MIME-Version: 1.0
From: Douglas Foster <dougfoster.emailstandards@gmail.com>
Date: Thu, 31 Mar 2022 07:13:57 -0400
Message-ID: <CAH48ZfwJrDK9oCpiF=-4snWs_Vu=veHo7Daka1uwTD3WK8CwWA@mail.gmail.com>
To: IETF DMARC WG <dmarc@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000b090e705db81c2f2"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/0GneHJlHKUTMhZ26k581HK5gqiE>
Subject: [dmarc-ietf] Tree Jump method - reporting targeting
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Mar 2022 11:14:11 -0000

While the PSL can determine an organizational domain from any From address,
the Tree Jump method only works if there is a single-subdomain DMARC policy
to contain the orgname=FQDN token.    This means that we would need to
encourage domain owners to publish policies on each domain that sends mail,
something that is not required now.

But if I understand the specification correctly, every DMARC policy serves
to partition the reporting scope, with results for subdomains sent to the
subdomain target, and results for the organizational domain sent to the
organizational domain target after excluding the separately-reported
subdomain results.    Domain owners may be reluctant to publish
single-domain policies because they do not want this partitioning.

Consequently, it seems desirable to have a reporting preference indicator
for DMARC policies on subdomains:    ReportTargets=(self, org, both).
 When ReportTargets=org, the rua=address could be omitted, since the rua
destination will be taken from the organizational domain policy.
 ReportTargets=org would allow the domain owners to publish
single-subdomain policies without altering the reporting structure, and
without replicating a specific address in multiple policy records.