Re: [dmarc-ietf] DMARC2 & SPF Dependency Removal

Seth Blank <seth@valimail.com> Wed, 14 June 2023 10:46 UTC

Return-Path: <seth@valimail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E73BC14CE39 for <dmarc@ietfa.amsl.com>; Wed, 14 Jun 2023 03:46:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=valimail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ir88ZEiUwE6H for <dmarc@ietfa.amsl.com>; Wed, 14 Jun 2023 03:46:40 -0700 (PDT)
Received: from mail-lj1-x22d.google.com (mail-lj1-x22d.google.com [IPv6:2a00:1450:4864:20::22d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A435CC14CE29 for <dmarc@ietf.org>; Wed, 14 Jun 2023 03:46:38 -0700 (PDT)
Received: by mail-lj1-x22d.google.com with SMTP id 38308e7fff4ca-2b34969e65fso6263281fa.3 for <dmarc@ietf.org>; Wed, 14 Jun 2023 03:46:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=valimail.com; s=google2048; t=1686739597; x=1689331597; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=PaP1HYwa/36HG88a/ag+FLNhFDh4X6l8wxslkvWWDRs=; b=WSbDLV82GFFBVdDfZjboHcDPLauMU5A0ru5N9sOMYLxGLkYPDOCPfOuPq6sf+KYYXf IYjytQXPpu58VzNhbXL2CNUcnujtsenavj5vGnNkhmDrQmpsLbxaxakM8iiOrE5mvzSb k239UW8d5D3G4j/IaF0EWanPR26pRFP0FCmhr6EXtFdaZ6IxuIhVm+kTvY/yL6WLDKGI KlLLF4HJjiXYDbdtSqMR0nBs6Jh16OLoPjBQ7Kdi/c8X2sRy4WlkTO9pOFvgZAYXjmgP 23YnQmcN9CiyiUcvd1ppGRMrXAU5C1GF5s1xn9M7kAEC6wlP5DwOgtpQgnIUv2WivDyJ 9phw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1686739597; x=1689331597; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=PaP1HYwa/36HG88a/ag+FLNhFDh4X6l8wxslkvWWDRs=; b=KIxqbrhapzt3Hg/QScTljPD8QIVCRTejAbMNnaM5OF9ROkhU3Xjoy7gnRe039JpkV4 zLOM0pOPldgNNW1357j5Pa2GB8pUB2WSgrAYwCBNULze5BOQV7mKEeqg945u1iQqKve9 DbQ7eo+52FukFQZOqXbS5lYWoxUq9meKjdv64DGMYAA8UxiSmQfTuFaC+3YfVZp3msTb TvPBXeV9gRivwkP3eIJAAnYEzzteU4GsCVQsX3OuJugzDpppyJ8s+yN5LKXC4Y9NbB0i P3iyhlLClJz0OF1OP98FPNbPyS/rDFA8UmcPWT/pF5z/hE5HQg6yy4NuyLva1kyMq9F+ MxsQ==
X-Gm-Message-State: AC+VfDwf18+9GhUiyvBY9Te6nu8KpwZSOZwQSXa8orxnbM4m1RbI4ciu fFVPF+nwLpqSDv03kAOHHPrOjmk2K7pdmbS6rYTIQ+PJJamyUFGKUhw=
X-Google-Smtp-Source: ACHHUZ5mxuJbyukpYHM3Jzh1J6joNuagTaYfjm9JYuC0R5Ny6PLWY1HOIiLh9CBP20P20E5+irkpvlYPndkAQjIv/10=
X-Received: by 2002:a2e:a0d5:0:b0:2b1:c613:4b9d with SMTP id f21-20020a2ea0d5000000b002b1c6134b9dmr6500531ljm.4.1686739596629; Wed, 14 Jun 2023 03:46:36 -0700 (PDT)
MIME-Version: 1.0
References: <30BB83B2-B454-41B8-992B-8E2569802D9C@1und1.de> <D225D7FC-C570-4B63-A694-9F16DB1F33E1@kitterman.com> <CALaySJKwuOK-81dW2H9dtURxa5mLQDUNo+MWcs+Hho8N+yP9qg@mail.gmail.com> <2817813.dRqVH37e0G@localhost> <CALaySJJbPFBAV_7mZaARYWuMzuX+74r2Cm0jD+z92_iuFRn_MQ@mail.gmail.com> <25736.57534.195344.782189@fireball.acr.fi> <CAL0qLwYN5ynyJkszd3i3mY-RwO3NCwurCjBY5DhidC=FuxCXJg@mail.gmail.com>
In-Reply-To: <CAL0qLwYN5ynyJkszd3i3mY-RwO3NCwurCjBY5DhidC=FuxCXJg@mail.gmail.com>
From: Seth Blank <seth@valimail.com>
Date: Wed, 14 Jun 2023 11:46:25 +0100
Message-ID: <CAOZAAfMEjksvM3x66QSPqTX8-869_eatnGYght3XYi-2fJ3VbA@mail.gmail.com>
To: "Murray S. Kucherawy" <superuser@gmail.com>
Cc: Barry Leiba <barryleiba@computer.org>, Scott Kitterman <sklist@kitterman.com>, Tero Kivinen <kivinen@iki.fi>, dmarc@ietf.org
Content-Type: multipart/alternative; boundary="0000000000007c6b0505fe14aad2"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/aFCtU0uMAKewcFNGxn5y-Oauj5s>
Subject: Re: [dmarc-ietf] DMARC2 & SPF Dependency Removal
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Jun 2023 10:46:44 -0000

At M3AAWG a couple of years ago, a VLMB said that 60% of the DKIM errors
they saw were obvious human error in the publishing of keys.

This is why I’ve been pushing (through M3AAWG, and hopefully eventually via
the appropriate working groups here) the need to automate publishing of
DKIM keys. They’re public after all, and a human (and generally, multiple
humans) shouldn’t need to be in the critical path of getting a key from a
sending system UI and then getting it published properly in DNS.

My main point on this whole thread is there’s a lot of theory, but as
Tevo’s data shows, the reality of these deployments and their challenges is
far trickier.

I’m still working with Todd to bring our own data on SPF to the working
group.

Seth, as an individual

On Wed, Jun 14, 2023 at 11:10 Murray S. Kucherawy <superuser@gmail.com>
wrote:

> On Tue, Jun 13, 2023 at 10:34 PM Tero Kivinen <kivinen@iki.fi> wrote:
>
>>         DKIM failures
>>         ================================================================
>>         36.34%  26619   invalid DKIM record
>>
>
> This is staggering.  Can you characterize what the most common
> malformations are?
>
> -MSK
> _______________________________________________
> dmarc mailing list
> dmarc@ietf.org
> https://www.ietf.org/mailman/listinfo/dmarc
>
-- 

*Seth Blank * | Chief Technology Officer
*e:* seth@valimail.com
*p:*

This email and all data transmitted with it contains confidential and/or
proprietary information intended solely for the use of individual(s)
authorized to receive it. If you are not an intended and authorized
recipient you are hereby notified of any use, disclosure, copying or
distribution of the information included in this transmission is prohibited
and may be unlawful. Please immediately notify the sender by replying to
this email and then delete it from your system.