Re: [dmarc-ietf] Overall last-call comments on DMARC

"Murray S. Kucherawy" <superuser@gmail.com> Mon, 01 April 2024 14:35 UTC

Return-Path: <superuser@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 63716C14F74E for <dmarc@ietfa.amsl.com>; Mon, 1 Apr 2024 07:35:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.094
X-Spam-Level:
X-Spam-Status: No, score=-2.094 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WGdFLRL68tXd for <dmarc@ietfa.amsl.com>; Mon, 1 Apr 2024 07:35:43 -0700 (PDT)
Received: from mail-ej1-x62f.google.com (mail-ej1-x62f.google.com [IPv6:2a00:1450:4864:20::62f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8D132C14F747 for <dmarc@ietf.org>; Mon, 1 Apr 2024 07:35:43 -0700 (PDT)
Received: by mail-ej1-x62f.google.com with SMTP id a640c23a62f3a-a46f056c29eso149762966b.1 for <dmarc@ietf.org>; Mon, 01 Apr 2024 07:35:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1711982141; x=1712586941; darn=ietf.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=JmIv1Bb+hHxw9zw2UtUaldpGoLoB9zu5FkdXJRP3W/4=; b=XmJzzeTJEU5YeQQNdvyYaRTGH7Swa2HtW6RNXuTDU68c8UY251a/BhJRMCX5DvNN5F c1H70ZoucIbx/gQGmwRr9qyKCnU0zHsja4ecS0l2NuJuC4Qe5uyFyG+Pw0mHKF94sXD+ mtJp2V6mTmrlrynlF3nDRTjUzljXVXffSjo9ekrusUxEoNXasyEE+HqZIeAh17uR1XL1 0VknA4JauV428+B/algo/27mxr8RUQqTT7nEcyxhpkBor+V7nXJAR8x0nymgE+dn7y9K w5vu04edGDERmV86CKv9n8nrDp9xYBAIVwhwIMaq689cuohBIc+fYQ8rLfOLuxmNeo+M ZfGg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1711982141; x=1712586941; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=JmIv1Bb+hHxw9zw2UtUaldpGoLoB9zu5FkdXJRP3W/4=; b=CTDToONWERPyu9WmoJl++81p3ZOascWFF14hghc1jrpu4d0OCOeHCZKjpwjFvsR6is DudyEcpQP8F/tjBgLRLJ0ozRZ3Wm4n4nDOeOe5VjQl6iu9RORkVL4mfNXJf1yv01XRnP +S1fC749J31USq2gL4k5yxQE+yPA+4weITM0q/yG+/sqrEGozDRSaiWI9PyPQ3j0tU52 k03Gr6UW8QRfyQBCn9nYBNtnXWx0KGO23Dx60TvPltv74XiMcS5afMWnl/Tg3QzWX/BK XkMzvbKPTE3yIujOcrAZVbRVPUdQ1RUMWrzyDmZR7b+WYtpCQKUNdIIml1XE723J6Pel n3hQ==
X-Gm-Message-State: AOJu0YwrCGMTHAuHMXrmsR9Ew3T/YKUYUhH/Vzqv/nJWD6IYDgA8j1AL 4sWzkGF7ILPa22Wj5vRPu8AWvL9y4bywGezVi3LdpwuwokVuXQVRR43zkuQc771ATOaBeRA31UP gtA6N47G2xArkHMKHo9J1K5sum8kgT7Gttoo=
X-Google-Smtp-Source: AGHT+IE/CjcaYkAxbH9PMrz/XRldORqaO/OqB6DVohsHGf5NejbahcfbivSVPu8G1ZD5gqn2Ti47pBKitZOq5JzBj70=
X-Received: by 2002:a17:906:c79a:b0:a47:2016:4c9e with SMTP id cw26-20020a170906c79a00b00a4720164c9emr6053472ejb.5.1711982140756; Mon, 01 Apr 2024 07:35:40 -0700 (PDT)
MIME-Version: 1.0
References: <CFEA2796-9213-4847-836B-81E8770973F5@bluepopcorn.net> <5208da1b-ecfb-4d41-8506-a734a27ab3a0@tana.it>
In-Reply-To: <5208da1b-ecfb-4d41-8506-a734a27ab3a0@tana.it>
From: "Murray S. Kucherawy" <superuser@gmail.com>
Date: Mon, 01 Apr 2024 07:35:28 -0700
Message-ID: <CAL0qLwbnSe77Wdt+M8bi2pBmZFCZjDUQc6je9bjCzP5TQ0N6XA@mail.gmail.com>
To: dmarc@ietf.org
Content-Type: multipart/alternative; boundary="0000000000005c9bc1061509e77b"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/HbYCfmTNeY4x3fohsCMYyOYCFXo>
Subject: Re: [dmarc-ietf] Overall last-call comments on DMARC
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Apr 2024 14:35:47 -0000

On Mon, Apr 1, 2024 at 4:44 AM Alessandro Vesely <vesely@tana.it> wrote:

> > * Mailing lists — Mailing list operators, including ietf.org, have had
> to
> > implement rewriting of From addresses such as user@example.com becomes
> > user=40example.com@dmarc.ietf.org when a p=strict or p=quarantine
> policy is in
> > place. This works to some extent for IETF, but there is an enormous
> number of
> > mailing list operators, each of whom would need to implement address
> rewriting.
> > While address rewriting is not the recommended solution, it is widely
> used
> > because of the widespread inappropriate use described above.
>
> By now, most mailing lists arranged to either rewrite From: or not break
> DKIM
> signatures.  We all hope those hacks are temporary.
>

What do you mean by "temporary", given the time scales that have already
passed since RFC 7489 saw wide deployment?  Do you envision those
techniques ending sometime soon?

If "most" mailing lists have arranged rewrites or non-mutation, and this
appears to be working, are there specific techniques we should standardize
here?


> ARC provides a protocol
> whereby a mailing list can certify its behavior to an end receiver.
> Unfortunately, we are still missing a protocol whereby trusting an ARC
> sealer
> can be established by a receiver for each mail stream.  We are halfway
> across
> the ford.
>

Are you suggesting we need some standard way to calculate and/or share a
sealer's reputation for any of this to work?

-MSK, p11g