Re: [dmarc-ietf] p=quarantine

Dave Crocker <dcrocker@gmail.com> Sat, 12 December 2020 18:42 UTC

Return-Path: <dcrocker@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7DE0C3A127C for <dmarc@ietfa.amsl.com>; Sat, 12 Dec 2020 10:42:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, NICE_REPLY_A=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EcV-fxHqHYJY for <dmarc@ietfa.amsl.com>; Sat, 12 Dec 2020 10:42:28 -0800 (PST)
Received: from mail-pg1-x52c.google.com (mail-pg1-x52c.google.com [IPv6:2607:f8b0:4864:20::52c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 47F2D3A0D6F for <dmarc@ietf.org>; Sat, 12 Dec 2020 10:42:28 -0800 (PST)
Received: by mail-pg1-x52c.google.com with SMTP id w16so9578833pga.9 for <dmarc@ietf.org>; Sat, 12 Dec 2020 10:42:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-transfer-encoding:content-language; bh=o0KbBaAMPOdMRyAHm+zAJphsmRYRhCAN0nZhlhTxbrI=; b=VG3X7i4FVMNVj98kdHYe7wLQe+KSLvmsKkyuzGXrF0gKE+UsR4eFUr5agNZsrLkiGp Cxr3YiVBCmLz4cXqIeB+fejnluN+sPp7Pp9zAoDHqxoQZmekCitu/ZDDQ8xG+XSBuiW2 Y6HKqJat1jL8mOlBrxnXyOTVIoXXVBGswVmshREeRd+cc3gvhrcImb96m9k8dyGnGs6l N7ieSRjl2x+oLDq9vR+YlKDFxnlzlu8Qz9znNZpP0MnothxIiFLm7glUCyg55V7pdc4i LGfXQ9Yh0GSw+gmYrJK11xCI59CNp0RgbKkemYyfQwM2gW+m+PpntLyxoIm02wZ9dLsf JjAQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding :content-language; bh=o0KbBaAMPOdMRyAHm+zAJphsmRYRhCAN0nZhlhTxbrI=; b=UOpZI7j5Vr/Fzy9xuw/NJtg2xpWv6aMe9/N3YcSLAQV93qiaS3pvT7PyJQWli0S15y 51Gq4YQuwQ1xBVKc6lw4TWOSWwKbgAt8cCoA4Njl4UsX/+rXYBkkGxlKKbqekUz/JOEs IxPwiUwkT0R6iww94ZgaTKT/r1pCZIUwdqz6KIBmS61lsRU+x1VQ9MJNFce10D6fFSE2 CXuoNaEzpHuFS1zFL/0uMOceCvEDj1+rZYgNe0EDeSt0ktmuUS07ZTznnY9zFm8QU+lJ JaHcz/fY8j/A/qpiXOTuu8tqVt4IUnh6GtomW2T7KbWQnqi8irK6EIF5XS0vsmrcYMxO 8i/A==
X-Gm-Message-State: AOAM532GSEx2zxuZjNw3hWIPScc2bE1l9keAzc1zvus3lOW3fj/+PZrz 7dXrifC520iLPWLMkjAIKFdJnEhRQYQ=
X-Google-Smtp-Source: ABdhPJyzsDcwtDWbiE50tWAuVL98wPO0kiDe8gSE3MKEN4RjHrHgZqsnIHxTEHmuLIu+Kj7lBDB3og==
X-Received: by 2002:a05:6a00:7c7:b029:19d:bab0:bc90 with SMTP id n7-20020a056a0007c7b029019dbab0bc90mr17190569pfu.62.1607798547588; Sat, 12 Dec 2020 10:42:27 -0800 (PST)
Received: from [192.168.0.109] (c-24-130-62-181.hsd1.ca.comcast.net. [24.130.62.181]) by smtp.gmail.com with ESMTPSA id js9sm15390220pjb.2.2020.12.12.10.42.26 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sat, 12 Dec 2020 10:42:26 -0800 (PST)
To: John Levine <johnl@taugh.com>, dmarc@ietf.org
Cc: laura@wordtothewise.com
References: <20201211173722.6B4DF29782C7@ary.qy>
From: Dave Crocker <dcrocker@gmail.com>
Message-ID: <ea074aad-971b-abc6-d557-ea2f433b3cc7@gmail.com>
Date: Sat, 12 Dec 2020 10:42:25 -0800
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.5.1
MIME-Version: 1.0
In-Reply-To: <20201211173722.6B4DF29782C7@ary.qy>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/Nr1IkD7pO4Xw5dF_wIh2PLA4y8I>
Subject: Re: [dmarc-ietf] p=quarantine
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 12 Dec 2020 18:42:30 -0000

On 12/11/2020 9:37 AM, John Levine wrote:
> In article <1AC986FF-507B-4917-9C6D-D84E9337FC7A@wordtothewise.com> you write:
> aligned is not authorized by the domain owner and may be discarded or rejected by the recipient.
> Naah.
>
> p=reject: all mail sent from this domain should be aligned in a DMARC
> compliant way. We believe that unaligned mail is from unauthorized
> senders so we ask receivers to reject it, even though that might mean
> some of our authorized senders' mail is rejected too.


As soon as this specification text, here, contains language about how 
this information is to be used, should be used, or could be used, it 
crosses over into creating confusion about expectations of receiver 
handling.

It encourages misguided language such as the receiver 'overriding' 
sender policy.  The sender has no policies about receiver behavior, 
because there is no relationship between them. Using milder language 
here doesn't help, because readers typically do not read like legal or 
technical scholars.

DMARC provides information, not direction.

The spec already contains misguided perspective by talking about 
'policy' records and, even worse, "policy enforcement considerations".

If the document must contain language about receiver choices in message 
disposition, move it to an overtly non-normative discussion section that 
legitimately covers a wide range of things that receivers do or don't do 
(cast as things they might or might not do.)  And make sure none of the 
language hints at sender 'policy', overrides, or the like.


d/

-- 
Dave Crocker
dcrocker@gmail.com
408.329.0791

Volunteer, Silicon Valley Chapter
American Red Cross
dave.crocker2@redcross.org