Re: [dmarc-ietf] Header Rewriting

John Levine <johnl@taugh.com> Wed, 06 January 2021 19:11 UTC

Return-Path: <johnl@iecc.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B52F3A124C for <dmarc@ietfa.amsl.com>; Wed, 6 Jan 2021 11:11:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.852
X-Spam-Level:
X-Spam-Status: No, score=-1.852 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.248, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b=QYTvtaAV; dkim=pass (2048-bit key) header.d=taugh.com header.b=vrpXxuAh
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ETGqnqyx1z9g for <dmarc@ietfa.amsl.com>; Wed, 6 Jan 2021 11:11:29 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 55CE93A1216 for <dmarc@ietf.org>; Wed, 6 Jan 2021 11:11:28 -0800 (PST)
Received: (qmail 25952 invoked from network); 6 Jan 2021 19:11:28 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:cleverness; s=655e.5ff60b60.k2101; bh=oCP+l+LLPxZoOPP1H7eGSKs5zDdns/ue/F6Fkv2R8U8=; b=QYTvtaAVcGZk1+AHJbjgU54MOoNMJ7RD6//IvELGqp4oU6Pggv82/K6sF089WNAKM/gJw8U+yXKvg8I8Eqxq2iOKNAeWT+N9ZgNPpS8qcQtuYUpUd072lRek/M95mNp70wW65tZh9BAoj0LnDi7biqRcMGPQkmTF8bZU8ltS1NVCh737vdhrVro8t2SW8tj3h8uDTQOPeb9HpK42sfCm90T79gVKPY5ftdXxl9/LTafdaqZJSUQIYEEUHNU8q44gBWLCpY4n2hYBGaBK6dXRL+ILB8Qb7tU2ao4rI9xboT+/IjTI2aUw2QkfUT0F9i9kx8qCBVF+9M+dUSovqGgqEw==
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:cleverness; s=655e.5ff60b60.k2101; bh=oCP+l+LLPxZoOPP1H7eGSKs5zDdns/ue/F6Fkv2R8U8=; b=vrpXxuAhl9A0/CB+TxnXWx/vDC8I0TORBpBKzoU8yXkMqwoVBtE6RTH8nPUBmi8cZ5uVi/BfQWyVIb38BOyoRR6rnVJw88WJhclXZ0ApW0RbrvW0btv0gE9CC1HLSJzk/jTkU4ftHawlSCB6jzCdSyUPqbyoUbI/Js4dwKccsBUJvl3P+Xp09xuVDfoF4VdyOVg30MnVqgKpvktl8l3ARrj6AAixhwBloFM+vf4clcFkDoCIztsNn3jklMGbvvX00qWSdMQtHL2Sg5h9BGoLq5Z8UzC0J6vGDQWOQtt9oqMoT+NKWXldko+Fe/WwN/9MyFrk3IZZDp1Zw0FCfNnG/w==
Received: from ary.qy ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.2 ECDHE-RSA AES-256-GCM AEAD) via TCP6; 06 Jan 2021 19:11:27 -0000
Received: by ary.qy (Postfix, from userid 501) id 290BC5D043E4; Wed, 6 Jan 2021 14:11:26 -0500 (EST)
Date: Wed, 06 Jan 2021 14:11:26 -0500
Message-Id: <20210106191127.290BC5D043E4@ary.qy>
From: John Levine <johnl@taugh.com>
To: dmarc@ietf.org
Cc: laura@wordtothewise.com
In-Reply-To: <D3A51087-6E1A-465F-89CD-63172E8075D4@wordtothewise.com>
Organization: Taughannock Networks
X-Headerized: yes
Cleverness: minimal
Mime-Version: 1.0
Content-type: text/plain; charset="utf-8"
Content-transfer-encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/TQ-bR-A3UMqOS6QIKiHnEuN5HSM>
Subject: Re: [dmarc-ietf] Header Rewriting
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Jan 2021 19:11:38 -0000

In article <D3A51087-6E1A-465F-89CD-63172E8075D4@wordtothewise.com> you write:
>The header rewriting being proposed - that is header rewriting by the ESP so that the messages that
>go through their system are rewritten to point to the ESP and not the author of the message - means
>that the identity assertion is disconnected from the context of a message.
>
>Want to know what mail goes through ESPs? Bank mail, social media mail, marketing mail. Billions of
>emails a day go through ESPs that you have and have not heard of. 

It's even worse than that. Some ESPs are not very good at managing
their customers. Sendgrid, one of the larger ESPs, sends me a stream
of bank phishes, fake vaccine offers and (for symmetry I suppose)
antivax kookery mixed in with the legit bulk mail and some receipts
for real transactions. They do not have a good reputation and a great
deal of the mail they send goes straight to the junk folder where it
belongs.

Header rewriting is not any sort of solution to the problems that DMARC creates.

R's,
John