Re: [dmarc-ietf] finer grained org domain

Seth Blank <seth@valimail.com> Tue, 18 August 2020 16:59 UTC

Return-Path: <seth@valimail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4C8FA3A0FF1 for <dmarc@ietfa.amsl.com>; Tue, 18 Aug 2020 09:59:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=valimail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id moWzeitfbWLU for <dmarc@ietfa.amsl.com>; Tue, 18 Aug 2020 09:59:19 -0700 (PDT)
Received: from mail-wm1-x333.google.com (mail-wm1-x333.google.com [IPv6:2a00:1450:4864:20::333]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 53F653A1005 for <dmarc@ietf.org>; Tue, 18 Aug 2020 09:59:19 -0700 (PDT)
Received: by mail-wm1-x333.google.com with SMTP id x5so16882488wmi.2 for <dmarc@ietf.org>; Tue, 18 Aug 2020 09:59:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=valimail.com; s=google2048; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=3RBLFf7tmromE9hNs+aYVsKSDNfgDJNHF7iUMU63CTw=; b=Vd5raXyxkgqowHyAZ3MwMApAcB0h035y8/21RbXfJfin7J+fblZJ91ggkn3WzUwLyH m8BodiVaxHoldiSJpKTkn3fjtFrMCjv3LCbFbJCrAGhUpO5+JgnHi6VN3GCIWTY1Rf3R 7T7XbSY4+hTOTVEbhNm/fFEGDaWaETyAVPbhuko2ZvWC6GeOqgA8gmuPP5qFfG1aUGKr auiwLCvg2B8cUnMg8Z+vo1jTV5bPr3nnYlPooM/l+MgpLP6M6/Lfj+55pzyjPhnkr1qQ 8B/9RkRk6Ln0GCgCXzQ9KamYt5S9Uw+5TulcrSzOWc87gpq4arCJjN1vCrH8u/W2S6ul xltQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=3RBLFf7tmromE9hNs+aYVsKSDNfgDJNHF7iUMU63CTw=; b=ciPXmE3kqohdCXpwnUPiqTzEN2DmSdCYNiPyGb/0SWjHl88HE4zj4FVfCSfgnB0J/d kal1V3CpAPpOGvTjmnOGuOvRwcLk0huyeca7juAIvYgMTmgFkrEoHAlhO9nSw1hBzK89 BzSUKRe8eODNfkQr0+goL5mAaarUV22s9A6RvA3BIaCQCmZdCIZRy/FgJCqEn4N56ZCL DEl/hYLvXwz8iE6j8w0KaWusYGdnkwV2o2gYI2USR9wLcp7MfD8ERo9XF8xRGiCbuKmQ 2Z52ugALIKTOaS1oHErLeAkEqSmAaWvSZ/fnfVHhHg75CCPHUKmySca7FDGOLCZEVQex ePhA==
X-Gm-Message-State: AOAM531OOUdzSGCcZpEbZTAfpXXA7GXZfXCFeabi1jCuo3h2qxC8IKbK 9978xbfMkqnUPP3DkRWllL662gNjsQUOL1Fa4Lgr9Q==
X-Google-Smtp-Source: ABdhPJwcd7/lQvajihSNAnRmMZuJ9iPaUVhFV3Y5YyJBKWD5bvPkxX+wtJKOFqfjWY1ZfX1cXj/7UiniEKy5hLiYyIU=
X-Received: by 2002:a1c:9e11:: with SMTP id h17mr814878wme.106.1597769957571; Tue, 18 Aug 2020 09:59:17 -0700 (PDT)
MIME-Version: 1.0
References: <20200808023259.1D07F1E60C2D@ary.qy> <977bbb4f-c393-0314-df72-17f342f2f975@wisc.edu> <BY5PR13MB29990BCF8E40BEB37AEEE4AAD75C0@BY5PR13MB2999.namprd13.prod.outlook.com> <585c222c-e288-5328-ea36-4d554234c838@taugh.com> <CADyWQ+EaOV7=+EYPNRa7Q7FGfdUBV2fKmpW1pwCM9O5rVaRM4g@mail.gmail.com> <c66df642-b94c-63ca-c9fa-fb7255ad3090@dcrocker.net>
In-Reply-To: <c66df642-b94c-63ca-c9fa-fb7255ad3090@dcrocker.net>
From: Seth Blank <seth@valimail.com>
Date: Tue, 18 Aug 2020 09:59:06 -0700
Message-ID: <CAOZAAfNwestYMiwvDm9--jAzmFoh96ZqmRaQa1gujZQnxhc36Q@mail.gmail.com>
To: Dave Crocker <dcrocker@bbiw.net>
Cc: Tim Wicinski <tjw.ietf@gmail.com>, "dmarc@ietf.org" <dmarc@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000c117ef05ad29ced7"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/a5kuqMY4S6wM_JSdEcD2A6QSBik>
Subject: Re: [dmarc-ietf] finer grained org domain
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Aug 2020 16:59:22 -0000

There is a ticket for tree walk: https://trac.ietf.org/trac/dmarc/ticket/68

Please hold the conversation until the chairs open that thread.

Seth, as Chair

On Tue, Aug 18, 2020 at 9:49 AM Dave Crocker <dhc@dcrocker.net> wrote:

> On 8/18/2020 9:43 AM, Tim Wicinski wrote:
>
> I do think the tree walk deserves another look.   Years back when it was
> brought up,
> there was lots of talk of overloading resolvers. But as someone who spent
> the past
> several years looking at the DNS query data of good sized SaaS domains,
> DMARC lookups
> (or even DMARC NXDOMAINs) were on the low end of the spectrum.  Nowadays,
> all web
> properties point to CDNs, et al with 30 second TTLs.
>
> To be entirely obvious:
>
>      badactor.a.b.c.d.e.f.g.h.i.j.k.l.m.n.o.p.yougetheidea.example.com
>
> produces a possible denial of service attack.  hence, no tree-walking.
>
> d/
>
> --
> Dave Crocker
> Brandenburg InternetWorkingbbiw.net
>
> _______________________________________________
> dmarc mailing list
> dmarc@ietf.org
> https://www.ietf.org/mailman/listinfo/dmarc
>


-- 

*Seth Blank* | VP, Standards and New Technologies
*e:* seth@valimail.com
*p:* 415.273.8818


This email and all data transmitted with it contains confidential and/or
proprietary information intended solely for the use of individual(s)
authorized to receive it. If you are not an intended and authorized
recipient you are hereby notified of any use, disclosure, copying or
distribution of the information included in this transmission is prohibited
and may be unlawful. Please immediately notify the sender by replying to
this email and then delete it from your system.