[dmarc-ietf] Issue: Domain Owner policy in Section 5.8

Barry Leiba <barryleiba@computer.org> Wed, 24 August 2022 19:41 UTC

Return-Path: <barryleiba@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ABE3EC1524B5; Wed, 24 Aug 2022 12:41:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.413
X-Spam-Level:
X-Spam-Status: No, score=-1.413 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.248, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J3fXYXQ37gm0; Wed, 24 Aug 2022 12:41:37 -0700 (PDT)
Received: from mail-ed1-f49.google.com (mail-ed1-f49.google.com [209.85.208.49]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 16684C1524C5; Wed, 24 Aug 2022 12:41:34 -0700 (PDT)
Received: by mail-ed1-f49.google.com with SMTP id z2so23409009edc.1; Wed, 24 Aug 2022 12:41:33 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:cc:to:subject:message-id:date:from :mime-version:x-gm-message-state:from:to:cc; bh=ElYfQ15+L4k5LkXVIiipEU64DeHcNQlhRNAoLAROEd4=; b=arOk3YAxrWdY+7Nxl6427Y5hUMtxP33qtuvcCmUH/uPYXtZVfWSrrVUVksCd3XgRSD NgMIsgSG5syBxYFxNTL5TLViP2vMdOEPM94clZ7UY+PsZPPxVB6eu1Id1Oq8kbuzwKTv a5/6h46lunrZv4Q8SMuSSRBl0r0vqLAE5+Fg8wAypxZ2ZaEN0V4+mpOrL5L8C50UMHKx m6Vwzjn/XQFThvzVhqAs5vqPYdYjxD368xNDt8aGmkLkA2TtV93ESRNJceFl4U9/zVnG FLfFID8YyO2vWFXUPlzqJra1fDhYdOsKdVvWQPp/1x8aLCcIhFDy6ticx/defbS0iWnK +wiA==
X-Gm-Message-State: ACgBeo2B6FIGeRujcIT3wGfzxNwH+hvKow1U7g1EKaN6R3qjAH/AH0aI ZGZ9C40Lx5tHbxbP8m5EZ88PcqmPvODby/PjQOof59TRQVA=
X-Google-Smtp-Source: AA6agR4aLPlYOrlZaIaYf2VZTsT/So/hWQ/ZhwVYOJsd1AR34WjA2x6poVj9hI+MHkD6W5/h1+bxfolqUEq9h0LowIA=
X-Received: by 2002:a05:6402:e94:b0:443:e3fe:7c87 with SMTP id h20-20020a0564020e9400b00443e3fe7c87mr474863eda.144.1661370091937; Wed, 24 Aug 2022 12:41:31 -0700 (PDT)
MIME-Version: 1.0
From: Barry Leiba <barryleiba@computer.org>
Date: Wed, 24 Aug 2022 15:41:20 -0400
Message-ID: <CALaySJ+hZTWhKmNxffsbhf6qQHR0eK_4YqagUohJFBAQ+gYffg@mail.gmail.com>
To: draft-ietf-dmarc-dmarcbis.all@ietf.org
Cc: IETF DMARC WG <dmarc@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/5YoxH5ysLaB-1FU0er4htzRdkeo>
Subject: [dmarc-ietf] Issue: Domain Owner policy in Section 5.8
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Aug 2022 19:41:39 -0000

— Section 5.8 —

   Mail Receivers MAY choose to accept email that fails the DMARC
   mechanism check even if the published Domain Owner Assessment Policy
   is "reject".  Mail Receivers need to make a best effort not to
   increase the likelihood of accepting abusive mail if they choose not
   to honor the published Domain Owner Assessment Policy.  At a minimum,
   addition of the Authentication-Results header field (see [RFC8601])
   is RECOMMENDED when delivery of failing mail is done.

As we discussed at IETF 114, I think it’s important that we be a bit
stronger here, and call the reader’s attention to RFC 7960.  Here’s my
text proposal, going with the “SHOULD” version, rather than the “MUST”
version:

NEW
   Mail Receivers MAY choose to accept email that fails the DMARC
   mechanism check even if the published Domain Owner Assessment Policy
   is "reject".  In particularly, because of considerations discussed
   in [RFC7960], it is important that Mail Receivers SHOULD NOT reject
   messages solely because of a published policy of “reject”, but that
   they apply other knowledge and analysis to avoid rejection of
   legitimate messages, harm to the operation of mailing lists, and
   the like.

   Mail Receivers need to make a best effort not to
   increase the likelihood of accepting abusive mail if they choose not
   to honor the published Domain Owner Assessment Policy.  At a minimum,
   addition of the Authentication-Results header field (see [RFC8601])
   is RECOMMENDED when delivery of failing mail is done.
END

(This also needs an informative reference to 7960 added.)

-- 
Barry