Re: [dmarc-ietf] Signaling MLMs

Alessandro Vesely <vesely@tana.it> Tue, 18 April 2023 16:25 UTC

Return-Path: <vesely@tana.it>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0AD14C151B0F for <dmarc@ietfa.amsl.com>; Tue, 18 Apr 2023 09:25:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=tana.it header.b="m4XvBmA3"; dkim=pass (1152-bit key) header.d=tana.it header.b="CWHN3UUt"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pUCZ-t7g5x7w for <dmarc@ietfa.amsl.com>; Tue, 18 Apr 2023 09:25:04 -0700 (PDT)
Received: from wmail.tana.it (wmail.tana.it [94.198.96.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8D733C14CE3B for <dmarc@ietf.org>; Tue, 18 Apr 2023 09:25:00 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=tana.it; s=epsilon; t=1681835096; bh=r7CYoEUEL9u5lXJKsTFrW+2xkLE4fSTwBqpSXybj/cE=; h=Author:Date:Subject:To:References:From:In-Reply-To; b=m4XvBmA3RVmvlFPZfmkKWj69K2qoOvggTeYQNb5XItfte4/zUXLP7fdiX+CMhCfRS MiZcTG5CvYvPqA5JTRNDw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tana.it; s=delta; t=1681835096; bh=r7CYoEUEL9u5lXJKsTFrW+2xkLE4fSTwBqpSXybj/cE=; h=Date:Subject:To:References:From:In-Reply-To; b=CWHN3UUtVOgIQW/bFnlLCDB08uK7JFRnnY50K26ffVMUsNyyxkK+tAgyHRXeqCGIZ XUEIbdzMVWs3Qx/7UUeBEB8ttv+TZ9/hmQVM60+o/OVmEiqyAVxzp2A40kTLux3BM0 8idnMg2eBKYu1RRUxuXtF8ZP+vqe9uMoB51Z0ObR01fm2Yb6X5b/8hcq6SqQq
Original-Subject: Re: [dmarc-ietf] Signaling MLMs
Author: Alessandro Vesely <vesely@tana.it>
Received: from [172.25.197.111] (pcale.tana [172.25.197.111]) (AUTH: CRAM-MD5 uXDGrn@SYT0/k, TLS: TLS1.3, 128bits, ECDHE_RSA_AES_128_GCM_SHA256) by wmail.tana.it with ESMTPSA id 00000000005DC0FA.00000000643EC458.0000476D; Tue, 18 Apr 2023 18:24:56 +0200
Message-ID: <10c5dcb4-4eca-b6f4-6a76-29faf2700f76@tana.it>
Date: Tue, 18 Apr 2023 18:24:56 +0200
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.9.0
Content-Language: en-US, it-IT
To: dmarc@ietf.org
References: <5DAE096A-B547-4569-A3C6-34ED9EC91B2D@isdg.net> <AA303EAF-76DA-4FAD-877D-C7B0143E21D3@marmot-tech.com> <643CB79E.7060309@isdg.net> <01ffe451b5f6e748cdcd295221f085e4@junc.eu> <D791743D-9E7F-4724-8181-44EF6148F5B3@isdg.net> <c19d02bdc96f8f016af430710ccb4247@junc.eu>
Authentication-Results: tana.it; auth=pass (details omitted)
From: Alessandro Vesely <vesely@tana.it>
In-Reply-To: <c19d02bdc96f8f016af430710ccb4247@junc.eu>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/WtGN6BC0Y7VcdchkgtUYyCcfGg0>
Subject: Re: [dmarc-ietf] Signaling MLMs
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Apr 2023 16:25:11 -0000

On Tue 18/Apr/2023 00:48:30 +0200 Benny Pedersen wrote:
> Hector Santos skrev den 2023-04-17 20:55:
> 
>> One solution is for the junc.eu domain to add an ATPS authorization
>> record for ietf.org [1] to the junc.eu [2] zone:
>>
>> pq6xadozsi47rluiq5yohg2hy3mvjyoo._atps  TXT ("v=atps01; d=ietf.org;")
> 
> retest


What's the point of wearing an atps record if it's not called out in a DKIM signature?  (I wouldn't have tested it anyway).

What's the point of ARC-sealing a message which is not arrived from an external ADMD?


I'm rather happy with the amount of gibberish I currently get.  For this Benny's message it was:

Authentication-Results: wmail.tana.it;
   spf=pass smtp.mailfrom=ietf.org;
   dkim=pass reason="transformed" header.d=junc.eu;
   dkim=pass (whitelisted) header.d=ietf.org
     header.b=yiVUz1hG (ietf1);
   dkim=pass (whitelisted) header.d=ietf.org
     header.b=yiVUz1hG (ietf1);
   arc=fail (1 set(s)) smtp.remote-ip=50.223.129.194
Received-SPF: none (Address does not pass the Sender Policy Framework)
   SPF=HELO;
   sender=mail.ietf.org;
   remoteip=50.223.129.194;
   remotehost=mail.ietf.org;
   helo=mail.ietf.org;
   receiver=wmail.tana.it;
Received-SPF: pass (Address passes the Sender Policy Framework)
   SPF=MAILFROM;
   sender=dmarc-bounces@ietf.org;
   remoteip=50.223.129.194;
   remotehost=mail.ietf.org;
   helo=mail.ietf.org;
   receiver=wmail.tana.it;
Received: from mail.ietf.org (mail.ietf.org [50.223.129.194])
   (TLS: TLS1.3,256bits,ECDHE_RSA_AES_256_GCM_SHA384)
   by wmail.tana.it with ESMTPS
   id 00000000005DC0F0.00000000643DCCEC.00004A7D; Tue, 18 Apr 2023 00:49:15 +0200
Authentication-Results: wmail.tana.it;
     dnswl=pass dns.zone=list.dnswl.org
     policy.ip=127.0.9.2
     policy.txt="ietf.org https://dnswl.org/s/?s=1703"
Received: from ietfa.amsl.com (localhost [IPv6:::1])
	by ietfa.amsl.com (Postfix) with ESMTP id 7B53AC17B344
	for <vesely@tana.it>; Mon, 17 Apr 2023 15:49:04 -0700 (PDT)


Best
Ale
--