Re: [dmarc-ietf] Ticket #61 - Define and add a simplified (redacted) failure report

Jesse Thompson <jesse.thompson@wisc.edu> Thu, 10 December 2020 16:18 UTC

Return-Path: <jesse.thompson@wisc.edu>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 65F4C3A108F for <dmarc@ietfa.amsl.com>; Thu, 10 Dec 2020 08:18:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, MSGID_FROM_MTA_HEADER=0.001, NICE_REPLY_A=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=wisc.edu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kgAnJX3K9c7o for <dmarc@ietfa.amsl.com>; Thu, 10 Dec 2020 08:18:55 -0800 (PST)
Received: from wmauth2.doit.wisc.edu (wmauth2.doit.wisc.edu [144.92.197.222]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 90DB03A1085 for <dmarc@ietf.org>; Thu, 10 Dec 2020 08:18:55 -0800 (PST)
Received: from NAM12-BN8-obe.outbound.protection.outlook.com (mail-bn8nam12lp2169.outbound.protection.outlook.com [104.47.55.169]) by smtpauth2.wiscmail.wisc.edu (Oracle Communications Messaging Server 8.0.2.4.20190812 64bit (built Aug 12 2019)) with ESMTPS id <0QL400KMXTBHAVC0@smtpauth2.wiscmail.wisc.edu> for dmarc@ietf.org; Thu, 10 Dec 2020 10:18:53 -0600 (CST)
X-Wisc-Env-From-B64: amVzc2UudGhvbXBzb25Ad2lzYy5lZHU=
X-Spam-PmxInfo: Server=avs-2, Version=6.4.7.2805085, Antispam-Engine: 2.7.2.2107409, Antispam-Data: 2020.12.10.161216, AntiVirus-Engine: 5.79.0, AntiVirus-Data: 2020.11.17.5790001, SenderIP=[104.47.55.169]
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Hwr+BqEDA4qmFoDA8GPoPcTHZVA5yNhFcU94RJgRp1byPMkbV6zzOKNXOtwjYrMdSUPKSvNnqdZouPgH9bpBKu67djdh9/ReFUjr5y5E3z1HJ6EHvvKHLBs32gHNcWkFbv+HmI2k2kkKToozp9XXSMEx3dh8coHd5rqfZ9CzrquKsJLENx1t+XHQOkCjiw2vk6iUkVZ+enGvFyQAoqJjdW30cGcfC3mEiKJ9sk+bWYuVVp9ZfHD2ANTWg1agWTk7WkQYLCtw9wlCn25wV1txL2ac505Ad3l+ppvXILsBKp+ksgzA12yQvZYDT8K7nOFtuqmSPeXQfcOUdpNzHK2s2A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=CcjYqL+knCdg2RKS3vseollCQ9U7QNycMF67VMwnDoI=; b=fbOR3a5ZzfAVokvkI3HLsj7nY2+pLWaZ+i/F/PoIA6qbyAG33Le/YIy8djdBBt+dWufFdHeatwtowG7XTlzqfhr+T67eU9N8s2i17/lMq8cbu5dE3HMlPvpDOxybuaXZYqZaQxqL9rYpWNGI70d+DZWVmc9HMS2S/NkrFDEHDwqrjpT/9fLvMBSxJH3jguKW1KieA/iMHjgTtfKI2Of/VhUm+1Pyk0zcTymCLI97v8vlP6Evb7AOER7cvgZTv0mOxxyJrCMnoL8b6CXCeq01U8mCe1AeMc9I54PFNSzcMJ3a96iON8NH2phIH7CIgH7wru1xHJRv18wk/dcHv9co6A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=wisc.edu; dmarc=pass action=none header.from=wisc.edu; dkim=pass header.d=wisc.edu; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wisc.edu; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=CcjYqL+knCdg2RKS3vseollCQ9U7QNycMF67VMwnDoI=; b=pc4cuwW1WZl9YSveUhY0v5bVX0ahigQWHU0FpeDu/Ubrfkvt/ScenK8R+iiqjnvBE0WzIwHqxnPytMhOWV3BIkU5vftB5LagC3GDYMhZ6SbqJm2N8vTnBtSFByShB16mQGAXtwKrDt3rjtFHtc9FRLwPyl3p9AHS729yNcStScA=
Received: from PH0PR06MB7061.namprd06.prod.outlook.com (2603:10b6:510:21::8) by PH0PR06MB7605.namprd06.prod.outlook.com (2603:10b6:510:58::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3632.17; Thu, 10 Dec 2020 16:18:52 +0000
Received: from PH0PR06MB7061.namprd06.prod.outlook.com ([fe80::51ec:c9cd:3511:1bcc]) by PH0PR06MB7061.namprd06.prod.outlook.com ([fe80::51ec:c9cd:3511:1bcc%6]) with mapi id 15.20.3632.021; Thu, 10 Dec 2020 16:18:52 +0000
To: dmarc@ietf.org
References: <609e1c9b-cc4d-d7d1-0fa8-79f515c1eee4@tana.it> <5b50a8ee-8f35-8ca1-b03d-eb4f8e697108@wisc.edu> <CABa8R6uU+DLNo2y7di8PDryf2Uy78_x0tu10u4tQRzO4bN0NfA@mail.gmail.com>
From: Jesse Thompson <jesse.thompson@wisc.edu>
Message-id: <ee440fad-3b1c-0a39-4771-d025f9bbe606@wisc.edu>
Date: Thu, 10 Dec 2020 10:18:50 -0600
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:78.0) Gecko/20100101 Thunderbird/78.5.0
In-reply-to: <CABa8R6uU+DLNo2y7di8PDryf2Uy78_x0tu10u4tQRzO4bN0NfA@mail.gmail.com>
Content-type: text/plain; charset="utf-8"
Content-language: en-US
Content-transfer-encoding: 7bit
X-Originating-IP: [47.12.96.133]
X-ClientProxiedBy: CH0PR03CA0037.namprd03.prod.outlook.com (2603:10b6:610:b3::12) To PH0PR06MB7061.namprd06.prod.outlook.com (2603:10b6:510:21::8)
MIME-version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
Received: from [10.0.2.111] (47.12.96.133) by CH0PR03CA0037.namprd03.prod.outlook.com (2603:10b6:610:b3::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3654.12 via Frontend Transport; Thu, 10 Dec 2020 16:18:52 +0000
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: d07f43ba-95da-480e-a090-08d89d274907
X-MS-TrafficTypeDiagnostic: PH0PR06MB7605:
X-Microsoft-Antispam-PRVS: <PH0PR06MB7605BF53426D9551E114980DF6CB0@PH0PR06MB7605.namprd06.prod.outlook.com>
X-MS-Oob-TLC-OOBClassifiers: OLM:9508;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: Sw+Zwzya3DScQfFGpBZrjbtTrHE8yFfH3pqIDOqiN7mQ0+9yzosGyUgFuzPSnsCv5xobOojG6bT5YdloOQVsBqB6heYu3SmkIwDFk4OzstXJhelwLG/9dCHfDn+99VEDhcn5L8BB5NNolb4Vyzk4AOgT3kcrvFDJfh/qywqeCsUGsMaRD2gFEIE27t2SCB383nEnWQYw6KuzqL1B1tFMmEnlV/khHduvz/XgwB4XerAEXbBIlxeuYS4FSP9vJTC9coHkQHH3uWp7ikdsUehZRcogIUxVAOW7m81WlCN+LmcKew4r7Jn+wHxlNvOpX8IZ3Fzte7iqfJhKMtqXelKWApp3Sh45ibtWFyCdpOnnS1acVEYCDnvma8LnHHlyGz9JPeQbCHLWROTwp0zV7yqT9/KAHXy4aKukKQnrxa+ZfuE=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR06MB7061.namprd06.prod.outlook.com; PTR:; CAT:NONE; SFS:(376002)(346002)(366004)(136003)(66946007)(66476007)(956004)(44832011)(2616005)(4744005)(2906002)(8676002)(5660300002)(508600001)(26005)(36756003)(6486002)(786003)(75432002)(53546011)(31686004)(83380400001)(6916009)(16526019)(86362001)(8936002)(186003)(66556008)(16576012)(31696002)(43740500002)(45980500001); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData: GH9jaxavtnGMGgxaBqVQLR2LQ4u7FyCJtIrUAnFHzlTTjnmg4gt4olZ2n8wEMfXp3DEBCotxCXvVq48GAuzQTd45T2UUR94PQrpiDfLLWa40emlyW49/r2lYK0AuTzs9PrV8VfbYDIb1DlOTJOHO344SwcxEWIxx39jABOtBV6pbHd/nvBP3WAHCLv7yHi2HK6pTDhzARcPDesVOzPaLrGqdGDjfBsI809AC3XD0hVY+NNC91X+wrgWA5bHcp7z9G9kHjbXrscLdp43SSbqQSTY1zx0wSHAySxB86etK8I4zcZ0jLonYA5+1/CZbm0e91qoYXnVFnGDKn1uEOAhdBSjVLWGNP3fEnSRFFQWb631tMZJpia5QJDI2CgnNnvJc8GnbZlCGm/8+B7vEWdnesR+eBxM7NZSeo/V784YQI1tLHatSS3DaU5egmvd3Tijut3g1To0DTQFk6eO9l9XwOGbHb2RvZEA6o8Rx6zBAcYtWZieO3caOHA+UmR2BQ6JaGxT6zPBHq5unILt1zn5u83xbsK7q7g1hL2VkgCBGjo9Ppob7S29cJ1/Sv0pcA3B5gWAD/g08fwsayrtE+Mjj0tXlBY5uKJ9sEvf9Iz3LlySmF4F5H/DCnXVNrTeT7kvaCZbZmdQ8i6IuZQEgTPox3sGb+/4w8TOgYcHE1JHnjV8Iz1eD6Xak/+9ELHp4QkkxxaY66kHLggcRQG+/mNG9l/OZQWnYupdo78wjAuJ9V82XNlT/EDeWlHPeydFWC2wWZZfkOcFxonFhE0Vh849c7CvepaSD2jZ0mIZrGZKChemKvckaoVW0nzUJPb70f4gLQZxm2B2UqztXey1KyStvFfw5YyFjDco1/e9vx+NTU0flShDg1kzpOenpR9iyXyVRyLs2y45mnx7+ESzBls2VN9DpRHaoxeVJX2PSkWdW+vO6gStbgESS1ubsfy1iu2WmXBi81ezn1nOuQqCDmqojG5tz4pb6N9qnD1PZ4rWpVkjSqUmk+48YIH7ZnfhSLES4
X-OriginatorOrg: wisc.edu
X-MS-Exchange-CrossTenant-AuthSource: PH0PR06MB7061.namprd06.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Dec 2020 16:18:52.6481 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 2ca68321-0eda-4908-88b2-424a8cb4b0f9
X-MS-Exchange-CrossTenant-Network-Message-Id: d07f43ba-95da-480e-a090-08d89d274907
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: b9nwlkAPgXo8yue7t6j+XYhsct7Bs8QGIGiNOn9jljq31N/5/oo6bA8mJJOhJWb7pWavvS64Hv/3wtnUFtw6Jw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR06MB7605
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/beoToL8hCCLWGquZKFlnM6GH-NY>
Subject: Re: [dmarc-ietf] Ticket #61 - Define and add a simplified (redacted) failure report
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Dec 2020 16:18:57 -0000

On 12/9/20 6:12 PM, Brandon Long wrote:
> At best, we considered allowing RUF reports for cases where the dmarc domain was the receiver, ie if someone had a message that failed dmarc while sending to the same domain, then presumably the domain admin already has the power to view the message.
> 
> But, if you limit it to that level, then the domain admin could already theoretically do this themselves by having those messages delivered to some destination to look at them, or setting
> up their own forwarding rule to their dmarc analysts.

I agree with this.  With senders that have a relatively large volume, there is a very high probability that at least one of the recipients is local.  Most of the necessary information is probably already available in logs.

Jesse