Re: [dmarc-ietf] DMARC2 & SPF Dependency Removal

Tero Kivinen <kivinen@iki.fi> Thu, 15 June 2023 13:34 UTC

Return-Path: <kivinen@iki.fi>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C530C14CE51 for <dmarc@ietfa.amsl.com>; Thu, 15 Jun 2023 06:34:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=iki.fi
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cXMMjLAzRIP3 for <dmarc@ietfa.amsl.com>; Thu, 15 Jun 2023 06:34:45 -0700 (PDT)
Received: from meesny.iki.fi (meesny.iki.fi [195.140.195.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0349CC14CF18 for <dmarc@ietf.org>; Thu, 15 Jun 2023 06:34:44 -0700 (PDT)
Received: from fireball.acr.fi (fireball.kivinen.iki.fi [IPv6:2001:1bc8:100d::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: kivinen@iki.fi) by meesny.iki.fi (Postfix) with ESMTPSA id 4QhjvL1fX3zyYc; Thu, 15 Jun 2023 16:34:37 +0300 (EEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=iki.fi; s=meesny; t=1686836079; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XzC9kb5UoLckKTFa/5AXpExeQWOPron1TsMmCHWlqu4=; b=Hhmht6p4HuUisvNjzEbpCs3CBCiUXwWrTYtX95cc7RtzxxQyxbDLwx+vTj8xOYPpTs5H80 z9ocCL+uWaMxBe1o6KBJva9y8wKOfM6Uv5Uc3Xw+g1Icu60L0dUsy60kTrjGillSZbYgit AUBA7TjbXmOD59y5vx0fwWlUgzntTxY=
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=iki.fi; s=meesny; t=1686836079; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XzC9kb5UoLckKTFa/5AXpExeQWOPron1TsMmCHWlqu4=; b=rxN3EZ9gQ4fa/imKMC7RTtXWcJxMT6guDMFWP9T+ZH5CkWF6vs+Wo7diMvMAPvWgcRm/+Q 5+lyA09wuMTQ2MQMmX73Wsw8rJ7X9zW/1Nyq/izTNqZBwNAiruw/TaRbewYkZR9TDFK7ej A01GtwwKiMq2wT3elg5MSCx+lKNqtqo=
ARC-Authentication-Results: i=1; ORIGINATING; auth=pass smtp.auth=kivinen@iki.fi smtp.mailfrom=kivinen@iki.fi
ARC-Seal: i=1; s=meesny; d=iki.fi; t=1686836079; a=rsa-sha256; cv=none; b=KZtE/+hElnSMiLs2t3qPUEt8VfsLjq9iXZRsH7ohCz5sfEuEOwgs8VtxXH5pEvdeIArypS uXLZT0hfddqHaEE4N8YUELCBz9+UJ3vM6Xz2EN7SEjDlcRpQPfH1r/OrS7m0ds9VYxMcnf bRx8iEFTWh45q8yWLgtfac7zR4o9M5U=
Received: by fireball.acr.fi (Postfix, from userid 15204) id A333425C130F; Thu, 15 Jun 2023 16:34:35 +0300 (EEST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Message-ID: <25739.4971.579969.884210@fireball.acr.fi>
Date: Thu, 15 Jun 2023 16:34:35 +0300
From: Tero Kivinen <kivinen@iki.fi>
To: "Murray S. Kucherawy" <superuser@gmail.com>
Cc: Barry Leiba <barryleiba@computer.org>, Scott Kitterman <sklist@kitterman.com>, dmarc@ietf.org
In-Reply-To: <CAL0qLwYN5ynyJkszd3i3mY-RwO3NCwurCjBY5DhidC=FuxCXJg@mail.gmail.com>
References: <30BB83B2-B454-41B8-992B-8E2569802D9C@1und1.de> <D225D7FC-C570-4B63-A694-9F16DB1F33E1@kitterman.com> <CALaySJKwuOK-81dW2H9dtURxa5mLQDUNo+MWcs+Hho8N+yP9qg@mail.gmail.com> <2817813.dRqVH37e0G@localhost> <CALaySJJbPFBAV_7mZaARYWuMzuX+74r2Cm0jD+z92_iuFRn_MQ@mail.gmail.com> <25736.57534.195344.782189@fireball.acr.fi> <CAL0qLwYN5ynyJkszd3i3mY-RwO3NCwurCjBY5DhidC=FuxCXJg@mail.gmail.com>
X-Mailer: VM 8.2.0b under 26.3 (x86_64--netbsd)
X-Edit-Time: 11 min
X-Total-Time: 26 min
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/_2D5yhWC9E89KSheh8GXGWlGu3M>
Subject: Re: [dmarc-ietf] DMARC2 & SPF Dependency Removal
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Jun 2023 13:34:50 -0000

Murray S. Kucherawy writes:
> On Tue, Jun 13, 2023 at 10:34 PM Tero Kivinen <kivinen@iki.fi> wrote:
> 
>             DKIM failures
>             ================================================================
>             36.34%  26619   invalid DKIM record
> 
> This is staggering.  Can you characterize what the most common malformations
> are?

I think most of those are missing keys. I.e., there is no key in the
dns at all for that header.d and header.s. 

This might be caused by having some internal machine doing the DKIM
signing but not publishing the actual DKIM records in the dns at all.

Sometimes there is another DKIM record that will pass like this:

ARC-Authentication-Results: i=1;
	MTA-v4;
	dkim=none ("invalid DKIM record") header.d=ernieball.com header.s=ci-ernieball header.b=XXX;
	dkim=pass header.d=criticalimpactinc.com header.s=keyd header.b=XXX;
	spf=pass (MTA-v4: XXX)

Sometimes there that was the only dkim record and then the final
result is fail:

ARC-Authentication-Results: i=1;
	MTA-v4;
	dkim=none ("invalid DKIM record") header.d=autostadium.fi header.s=x header.b=XXX;
	spf=pass (MTA-v4: XXX)

Note, that those are not really failures, I calculated those error
messages from dkim=none result to the statistics, as it indicates that
there was DKIM record in email, but DKIM was not set properly, so in
sense it is DKIM error, but if I remember right DKIM specification
says that not having DKIM record, or having missing keys etc in dns
are no different from each other, so both are DKIM=none... 
-- 
kivinen@iki.fi