Re: [dmarc-ietf] Signaling MLMs

Hector Santos <hsantos@isdg.net> Mon, 17 April 2023 18:55 UTC

Return-Path: <hsantos@isdg.net>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B0E1BC1522AD for <dmarc@ietfa.amsl.com>; Mon, 17 Apr 2023 11:55:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.087
X-Spam-Level:
X-Spam-Status: No, score=-7.087 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_REMOTE_IMAGE=0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=isdg.net header.b="LJSFN/J6"; dkim=pass (1024-bit key) header.d=beta.winserver.com header.b="x/bRVx9h"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Cf11ble2u-4R for <dmarc@ietfa.amsl.com>; Mon, 17 Apr 2023 11:55:40 -0700 (PDT)
Received: from mail.winserver.com (mail.winserver.com [3.137.120.140]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 68EABC151B3F for <dmarc@ietf.org>; Mon, 17 Apr 2023 11:55:40 -0700 (PDT)
DKIM-Signature: v=1; d=isdg.net; s=tms1; a=rsa-sha256; c=simple/relaxed; l=17182; t=1681757737; atps=ietf.org; atpsh=sha1; h=Received:Received:Received:Received:From:Subject:Date: Message-Id:To:Organization:List-ID; bh=9Uy/ntpBg/l40ynq1RIqLhPtg 2NoNCjSK4EH5gjBULw=; b=LJSFN/J6cir1s0odBom4RTEXsSODQOB5HC7tfJjjU +HxQrEig5mf9kHGr5h4NLxwgyeHqnPD/mf/QhPaJohikEpqHfBRhK2P6dHzVzwXJ lT9wEsnl+yplStB6QuTF5IQiXm4hyrPRljW/N66tTnzfOHOU9L41D0Y9t2q9rtdI o8=
Received: by winserver.com (Wildcat! SMTP Router v8.0.454.13) for dmarc@ietf.org; Mon, 17 Apr 2023 14:55:37 -0400
Authentication-Results: dkim.winserver.com; dkim=pass header.d=beta.winserver.com header.s=tms1 header.i=beta.winserver.com; dmarc=pass policy=reject author.d=isdg.net signer.d=beta.winserver.com (atps signer);
Received: from beta.winserver.com ([3.132.92.116]) by winserver.com (Wildcat! SMTP v8.0.454.13) with ESMTP id 2150529957.1.5896; Mon, 17 Apr 2023 14:55:36 -0400
DKIM-Signature: v=1; d=beta.winserver.com; s=tms1; a=rsa-sha256; c=simple/relaxed; l=17182; t=1681757735; h=Received:Received: From:Subject:Date:Message-Id:To:Organization:List-ID; bh=9Uy/ntp Bg/l40ynq1RIqLhPtg2NoNCjSK4EH5gjBULw=; b=x/bRVx9hb1D81R1Q8ljtttb flk5j9USMvJ8K8GVYVlN0Qo4XgZRHq7iiArOyIyQUteuNBJX/2TQ4Qp8Lsk3Ctxq eE5UdSuAqR2LoIa8GzKrCO1wx0zZnU2GlmkTs0hCWZT2TEKae/6orDFcwgYdicvF jUmlvnUTT1OVk0g79DJY=
Received: by beta.winserver.com (Wildcat! SMTP Router v8.0.454.12) for dmarc@ietf.org; Mon, 17 Apr 2023 14:55:35 -0400
Received: from smtpclient.apple ([99.122.210.89]) by beta.winserver.com (Wildcat! SMTP v8.0.454.12) with ESMTP id 2596566426.1.4232; Mon, 17 Apr 2023 14:55:33 -0400
From: Hector Santos <hsantos@isdg.net>
Content-Type: multipart/alternative; boundary="Apple-Mail=_D6760FAF-0EB2-43DB-A46B-A7F51F3DE7D2"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.400.51.1.1\))
Date: Mon, 17 Apr 2023 14:55:22 -0400
In-Reply-To: <01ffe451b5f6e748cdcd295221f085e4@junc.eu>
Cc: dmarc@ietf.org
References: <5DAE096A-B547-4569-A3C6-34ED9EC91B2D@isdg.net> <AA303EAF-76DA-4FAD-877D-C7B0143E21D3@marmot-tech.com> <643CB79E.7060309@isdg.net> <01ffe451b5f6e748cdcd295221f085e4@junc.eu>
Message-Id: <D791743D-9E7F-4724-8181-44EF6148F5B3@isdg.net>
X-Mailer: Apple Mail (2.3731.400.51.1.1)
X-Comment: Missing recipient address appended by wcSMTP router.
To: dmarc@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/ZqrJecfOTCsaKc9UKF_8r-yneqM>
Subject: Re: [dmarc-ietf] Signaling MLMs
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Apr 2023 18:55:44 -0000


> On Apr 16, 2023, at 11:31 PM, Benny Pedersen <me@junc.eu> wrote:
> 
> Hector Santos skrev den 2023-04-17 05:06:
> 
>> Anyway, there are far too much waste in electronic mail, ADSP/DMARC
>> and this quest to resolve its issues, creating more junk, ARC, is not
>> getting anywhere.
> 
> ?, spamassassin 4, do something, i use fuglu in prequeue smtpd postfix, works for me atleast, it sometimes helps to be a gentoo ebuild maintainer, i still like to find proxy maintainers helping me
> 
> with arc its sadly appled AFTER mailman have scrampled dkim :/
> 
> arc sign/seal should be done on incomming mails, not on outgoing


Thanks for the information.

Just consider your message source. The header overhead is massively complex to read. It is really a waste on receivers.

The final Auth-Result for your message:


Authentication-Results: dkim.winserver.com;
	 dkim=pass header.d=ietf.org header.s=ietf1 header.i=ietf.org;
	 dmarc=fail policy=none author.d=junc.eu signer.d=ietf.org (unauthorized signer);
	 dkim=pass header.d=ietf.org header.s=ietf1 header.i=ietf.org;
	 dmarc=fail policy=none author.d=junc.eu signer.d=ietf.org (unauthorized signer);
	 dkim=fail (DKIM_BODY_HASH_MISMATCH) header.d=junc.eu header.s=default header.i=@junc.eu;
	 dmarc=dkim-fail policy=none author.d=junc.eu signer.d=junc.eu (originating signer);


One solution is for the junc.eu domain to add an ATPS authorization record for ietf.org <http://ietf.org/> to the junc.eu <http://junc.eu/> zone:

pq6xadozsi47rluiq5yohg2hy3mvjyoo._atps  TXT ("v=atps01; d=ietf.org;")
to authorize the signer domain ietf.org:

See the wcDMARC wizard:


https://winserver.com/public/wcDmarc


—
HLS