[dmarc-ietf] Amazon Comments to DMARC Extension to PSD

"Flaim, Bobby" <flaim@amazon.com> Wed, 17 July 2019 22:23 UTC

Return-Path: <prvs=094886937=flaim@amazon.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost []) by ietfa.amsl.com (Postfix) with ESMTP id 86F0A120168 for <dmarc@ietfa.amsl.com>; Wed, 17 Jul 2019 15:23:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -11.799
X-Spam-Status: No, score=-11.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=amazon.com
Received: from mail.ietf.org ([]) by localhost (ietfa.amsl.com []) (amavisd-new, port 10024) with ESMTP id 3KN1ZAirzr9k for <dmarc@ietfa.amsl.com>; Wed, 17 Jul 2019 15:23:21 -0700 (PDT)
Received: from smtp-fw-33001.amazon.com (smtp-fw-33001.amazon.com []) (using TLSv1.2 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9A9F01200F9 for <dmarc@ietf.org>; Wed, 17 Jul 2019 15:23:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazon201209; t=1563402201; x=1594938201; h=from:to:subject:date:message-id:mime-version; bh=+a7xhf3GCzGS6W3ha50Xs2YsOyPMBOOI7uhtEMpBF2M=; b=qh3SzWDg33zoI482LuTna9/TQndwBU5Ey/FeIFsyvX8EG2O1q75vXFK2 Pk4oH5STH119jXWgzC3zupXkxAgSuD/gZZJLBRHu0jZRwJvi4lMGaIVUE qxC2K+QRKuLnJe2/SoQ/6KBjKj7TQEZMiJbd6SINmPC6wr4gQNKH72ESd U=;
X-IronPort-AV: E=Sophos;i="5.64,275,1559520000"; d="scan'208,217";a="811856152"
Received: from sea3-co-svc-lb6-vlan3.sea.amazon.com (HELO email-inbound-relay-1e-27fb8269.us-east-1.amazon.com) ([]) by smtp-border-fw-out-33001.sea14.amazon.com with ESMTP; 17 Jul 2019 22:23:14 +0000
Received: from EX13MTAUWA001.ant.amazon.com (iad55-ws-svc-p15-lb9-vlan3.iad.amazon.com []) by email-inbound-relay-1e-27fb8269.us-east-1.amazon.com (Postfix) with ESMTPS id C71E6A1C5D for <dmarc@ietf.org>; Wed, 17 Jul 2019 22:23:13 +0000 (UTC)
Received: from EX13D21UWA004.ant.amazon.com ( by EX13MTAUWA001.ant.amazon.com ( with Microsoft SMTP Server (TLS) id 15.0.1367.3; Wed, 17 Jul 2019 22:23:13 +0000
Received: from EX13D06UEE001.ant.amazon.com ( by EX13D21UWA004.ant.amazon.com ( with Microsoft SMTP Server (TLS) id 15.0.1367.3; Wed, 17 Jul 2019 22:23:12 +0000
Received: from EX13D06UEE001.ant.amazon.com ([]) by EX13D06UEE001.ant.amazon.com ([]) with mapi id 15.00.1367.000; Wed, 17 Jul 2019 22:23:11 +0000
From: "Flaim, Bobby" <flaim@amazon.com>
To: "dmarc@ietf.org" <dmarc@ietf.org>
Thread-Topic: Amazon Comments to DMARC Extension to PSD
Thread-Index: AQHVPO44YsRAt9WVs0a2kY1gnuZlEA==
Date: Wed, 17 Jul 2019 22:23:11 +0000
Message-ID: <132DD4E4-616A-47F5-A4A3-681067C86DA6@amazon.com>
Accept-Language: en-US
Content-Language: en-US
user-agent: Microsoft-MacOutlook/10.10.b.190609
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: []
Content-Type: multipart/alternative; boundary="_000_132DD4E4616A47F5A4A3681067C86DA6amazoncom_"
MIME-Version: 1.0
Precedence: Bulk
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/VGuw8Eq8erWIkF9hcWPnSjyNnuw>
X-Mailman-Approved-At: Wed, 17 Jul 2019 15:44:44 -0700
Subject: [dmarc-ietf] Amazon Comments to DMARC Extension to PSD
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Jul 2019 22:26:36 -0000

Amazon supports this draft and effort .

This current DMARC extension (IETF DMARC PSD) draft<https://datatracker.ietf.org/doc/draft-ietf-dmarc-psd/> would make it easier for our direct customers (registrants) to setup a common DMARC policy for all their subdomains. With this extension they can set up the policy in one place, such as the SLD level (second level domain) and it will apply to any subdomain they create.  However, since feedback leakage can happen due to the nature of the IETF DMARC PSD solution, the following proposed alternative could be employed to address this issue.

Is the DEMARC defined for dog.animals.com<http://dog.animals.com>?

a.      Yes: then use it

b.      No: then look for DMARC on animals.com<http://animals.com>

Proposed Default Alternative:
a.      Is the DEMARC defined for dog.animals.com<http://dog.animals.com>?

a.      Yes: Then use it

b.      No: Is using the PSD DMARC explicitly permitted by the dog.animals.com<http://dog.animals.com> owner in some TXT record (means “delegated explicitly to the PSD”)?
1.      Yes: then look for DMARC onanimals.com<http://animals.com>
1.      No: terminate

The alternative proposal requires the registrant to explicitly set up the default.