Re: [dmarc-ietf] SPF follies, WGLC editorial review of draft-ietf-dmarc-dmarcbis-30

Tim Wicinski <tjw.ietf@gmail.com> Mon, 01 April 2024 16:38 UTC

Return-Path: <tjw.ietf@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6364C14CE40 for <dmarc@ietfa.amsl.com>; Mon, 1 Apr 2024 09:38:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.095
X-Spam-Level:
X-Spam-Status: No, score=-7.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LID4y5dM0UCl for <dmarc@ietfa.amsl.com>; Mon, 1 Apr 2024 09:38:29 -0700 (PDT)
Received: from mail-ed1-x533.google.com (mail-ed1-x533.google.com [IPv6:2a00:1450:4864:20::533]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E63C3C14CEFE for <dmarc@ietf.org>; Mon, 1 Apr 2024 09:38:29 -0700 (PDT)
Received: by mail-ed1-x533.google.com with SMTP id 4fb4d7f45d1cf-56d7a0cf96cso3043776a12.2 for <dmarc@ietf.org>; Mon, 01 Apr 2024 09:38:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1711989508; x=1712594308; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=Edayro1zGUq7CgSOh0BmISCUB9dDb1M1odtGjR2XyjY=; b=cCgmTUbl916piNAB+7HAYm5c3yt8u2xnldMdegWXz7PGvJ2O9zKlL8bnTp3LA+yYXV g3yMRTUYz7CSGA2w7E1N9ZSq9QMdNJqTN8JWGub+whH7OwLlL7mTPklwcEzdvaWCnPHz eSce1wVTkGTtZZWd/u0OL7PYjf/GoTuwniPaflBXj3BTF7ZlDppQC7KzrS5CPbWk3823 Qebq4icEOEWxghjfAi472xfN4AJtF7OnYOV8WSBPf5wyh7x2xgvu+N2z48UA1baevsiO lclFQ4lRud9KOjm1TSsMQ6Bnuu6X6QeCU4XZ8HnaiCUPzsXaDOzHau15ay75vjiBd22c 6IVw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1711989508; x=1712594308; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=Edayro1zGUq7CgSOh0BmISCUB9dDb1M1odtGjR2XyjY=; b=xHW5wLAkm5D5TsWZq+09iaVy+2hStr14JXvDsfZMAdR0NHh1zhs1l2AvRF6A2Vv+OS C0TJGARPZerZIl9+2K/Hks2OyWHJlz5uoS6jke6/q+E3Eb0xfOnm/KX4pU53SUnJIgMW UKOmz4GeuJC43hiHBKD6beV9D3LvQK02dQMAMo7bdn99q2zTaZovVqcfl/poFEfEMAHs roQtE2W1zR5zdENtWEwIFpR33rq+E+cFEJfoFl+eX9eKvUYqPlwZ56paT9WhCUgZa6ae jCvOdTg6glxBxC3vMCZlJXxDz6113m90TnCQf0Fx4pPU/JqdhNrH5wjm5Ys8iYhma4YG vorA==
X-Gm-Message-State: AOJu0YyLoUFW01kc9g81gQo2+SGhm7QMGcjZsd9qu/lBl1cfaV5H+znG yd8u1j13BnU1g0finId/YD3WvgWEG8z66ms+5lGlhzOnZIpFMUbT2Xyk8S7un/C2hFrSZwLbx8E Plthd+bwGstg4XuNIHxpcJmcbJ7klFKLi
X-Google-Smtp-Source: AGHT+IFc4+8esGk/FyX5lAJTpKpoPdxTQeckFmPI38ZSGT2CoGwQ5LT5d6BcF7utHfGEnvdfQs97h7R6+4yBmn2r/UQ=
X-Received: by 2002:a50:a455:0:b0:56b:863c:2c92 with SMTP id v21-20020a50a455000000b0056b863c2c92mr7155583edb.34.1711989507836; Mon, 01 Apr 2024 09:38:27 -0700 (PDT)
MIME-Version: 1.0
References: <eda55c54-c149-475c-8117-bfdf3885a883@tekmarc.com> <20240331180009.F36CD8687B50@ary.qy> <CAOZAAfP9tXi80Fi=ZkgPpGwHo1fDbdSOZwVcnuPDbbc2xQd-7A@mail.gmail.com> <lIU60SB3NeCmFAG+@highwayman.com> <CAL0qLwZt+bo4ydCVOQbfg6bQEv-ufXrrwr8Aege9Wsv7LgH=kA@mail.gmail.com> <CAOZAAfPtxdBwEthN26cgvAnAbQ70wym+2k0WjtKqNVf44=-vMg@mail.gmail.com> <MN2PR11MB435115B7428C63C1B1058D9EF73F2@MN2PR11MB4351.namprd11.prod.outlook.com> <CAJ4XoYfmyDykZGm9Gb1bxjz=pW_scqon3pDv-DRGHjFrnyCLoQ@mail.gmail.com> <CADyWQ+HbfegU=07gNyR-5Dby_71GNim4Nq-LyFerKHk1dV0=Nw@mail.gmail.com> <CAHej_8=OxfPySzx0p2xR7iRmfai=CdU6iADECUCZoHXr6qvxcg@mail.gmail.com>
In-Reply-To: <CAHej_8=OxfPySzx0p2xR7iRmfai=CdU6iADECUCZoHXr6qvxcg@mail.gmail.com>
From: Tim Wicinski <tjw.ietf@gmail.com>
Date: Mon, 01 Apr 2024 12:38:16 -0400
Message-ID: <CADyWQ+HneEkUs7SCaOxmbdz5VnqQAe8Vohq+8iFNBiUq-G1qTw@mail.gmail.com>
To: Todd Herr <todd.herr=40valimail.com@dmarc.ietf.org>
Cc: "dmarc@ietf.org" <dmarc@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000007950c206150b9ebd"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/BLmNR4jVsauVWV3ZzIdrGjg7fBY>
Subject: Re: [dmarc-ietf] SPF follies, WGLC editorial review of draft-ietf-dmarc-dmarcbis-30
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Apr 2024 16:38:33 -0000

On Mon, Apr 1, 2024 at 12:27 PM Todd Herr <todd.herr=
40valimail.com@dmarc.ietf.org> wrote:

> On Mon, Apr 1, 2024 at 12:17 PM Tim Wicinski <tjw.ietf@gmail.com> wrote:
>
>> I have to agree with Seth's comments that "security teams believe an SPF
>> hard fail is more secure".
>> I've been on the receiving end of that discussion more than once.
>>
>> Also, can we reference those two M3AAWG documents ?  That seems like
>> operational guidance.
>>
>>
> I'm digesting the threads for the purpose of preparing tickets to track
> the work, and I suspect one of the tickets will include, "Add reference
> to the following two M3AAWG documents":
>
>    1.
>    https://www.m3aawg.org/sites/default/files/m3aawg_managing-spf_records-2017-08.pdf
>    2.
>    https://www.m3aawg.org/sites/default/files/m3aawg-email-authentication-recommended-best-practices-09-2020.pdf
>
>
>

Todd,

Yes, those seem like the documents I found on the m3aawg site.

I had recently read the "Past and Future of the PSL" document to use as a
possible reference, but it did not seem to make sense to me.

tim