Re: [dmarc-ietf] From: munging, was Ratchets - Disallow PCT 1-99

Benny Pedersen <me@junc.eu> Fri, 23 July 2021 12:23 UTC

Return-Path: <me@junc.eu>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3B60C3A16A2 for <dmarc@ietfa.amsl.com>; Fri, 23 Jul 2021 05:23:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.4
X-Spam-Level:
X-Spam-Status: No, score=-4.4 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=junc.eu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LaiqwUUzCnhf for <dmarc@ietfa.amsl.com>; Fri, 23 Jul 2021 05:23:04 -0700 (PDT)
Received: from mx.junc.eu (mx.junc.eu [172.105.72.99]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B23453A16A0 for <dmarc@ietf.org>; Fri, 23 Jul 2021 05:23:03 -0700 (PDT)
Received: from localhost.junc.eu (localhost.junc.eu [127.0.0.1]) by mx.junc.eu (Postfix) with SMTP id 468337FA9C for <dmarc@ietf.org>; Fri, 23 Jul 2021 12:23:01 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junc.eu; i=@junc.eu; l=725; q=dns/txt; s=default; t=1627042981; h=from : subject : date : to; bh=aaGQyTj7LAS4HVN6BZfIMRR4e09reKlbE9wEMp4X0vg=; b=phg2t+PkpfnOOKMQRIJlRGGFJpTYI7EFZixG43LfPSrKxHhwPaL2ycTSvD8R3QW2LxeUi dC1qLLXF1LRYZLZkTyy6bXHdDomK0kYDpMl+JmEh6Nsf598m2wvypSjM35M6p6FseoMtS6F 42zg1RvfmPcTIMv/YDk1Lm8ddcwXoA4ZYeh/ilBI0kfm/aB2uRIFbvfDst1leHSGAL32Ydj gzVtKHLHSlH2xOrUaMIHik4VSMU2ix8RtzKfrLlqoqYvOeq0Tt9SaRNh4rb2kD8cXb8w2sh ss5Lmsabn9YbyNW5Zr42y/G6DnLfiCAiOUk22EA65SGaSMOi/Cm/NDGIE+Qw==
Received: from localhost.junc.eu (localhost.junc.eu [IPv6:::1]) by mx.junc.eu (Postfix) with ESMTPSA id 252D87FA8A for <dmarc@ietf.org>; Fri, 23 Jul 2021 12:23:01 +0000 (UTC)
MIME-Version: 1.0
Date: Fri, 23 Jul 2021 14:23:01 +0200
From: Benny Pedersen <me@junc.eu>
To: dmarc@ietf.org
In-Reply-To: <128283c2-2607-ecf1-b261-3839a52383e1@tana.it>
References: <20210722185106.15C9F24DEDF0@ary.qy> <8b90752d-d4ea-e242-4c59-1b340f9bc400@tana.it> <88e9cce0-5510-7818-275-525ab5fc97ff@taugh.com> <128283c2-2607-ecf1-b261-3839a52383e1@tana.it>
User-Agent: Roundcube Webmail/1.4.11
Message-ID: <324e6035bd8909039f0d16242a2f403f@junc.eu>
X-Sender: me@junc.eu
Organization: junc.eu
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/M6HKN-G-31VbOedvKeKB9r2TlBU>
Subject: Re: [dmarc-ietf] From: munging, was Ratchets - Disallow PCT 1-99
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Jul 2021 12:23:10 -0000

On 2021-07-23 12:08, Alessandro Vesely wrote:

> https://mailarchive.ietf.org/arch/msg/dmarc/KvSFv66Mz8UipXQ0477UgO5WKio/

all this is solved if maillists stop dkim signing of non origination 
postings and only do the arc sealing so all dmarc testers can see 
originating spf, dkim pass

take sendgrid, thay forwarded netflix phishing emails, and thay belived 
dmarc protected there ignorance to some kind out off there services

never trust a forwarding server that does there own dkim signing, period

dmarc needs openARC testing to all above to work, then maillist can 
break maillists to there own stupid needs without breaking dkim cant be 
verified on dmarc recipient servers

hope the best for the future