Re: [dmarc-ietf] Proposed text for p=reject and indirect mail flows

"Brotman, Alex" <Alex_Brotman@comcast.com> Tue, 28 March 2023 16:36 UTC

Return-Path: <Alex_Brotman@comcast.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B521C151524 for <dmarc@ietfa.amsl.com>; Tue, 28 Mar 2023 09:36:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.094
X-Spam-Level:
X-Spam-Status: No, score=-2.094 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=comcast.com header.b="fjlqp+S6"; dkim=pass (1024-bit key) header.d=comcastcorp.onmicrosoft.com header.b="j/K5vjX+"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vQuPX1N6m_fI for <dmarc@ietfa.amsl.com>; Tue, 28 Mar 2023 09:36:44 -0700 (PDT)
Received: from mx0a-00143702.pphosted.com (mx0a-00143702.pphosted.com [148.163.145.77]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B9248C14CF13 for <dmarc@ietf.org>; Tue, 28 Mar 2023 09:36:44 -0700 (PDT)
Received: from pps.filterd (m0156892.ppops.net [127.0.0.1]) by mx0a-00143702.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 32SFCuNh017437 for <dmarc@ietf.org>; Tue, 28 Mar 2023 12:36:44 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comcast.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=20190412; bh=BpjIANpVAxebUPLcTN1NwTuBv4noTcA6v3pR9Rx6fZ0=; b=fjlqp+S6s2RzLNr7PGRqn0i7Lz+HXi/0YCsbFF1leJ3ADl2tdpD6anst1bbpS4jEKXck DtmMuEX5E4Muar7dmNY/1PBc0Fo4kUMmHr8vXqJ36ghe9MwrLJCqnrcLSWRxVrvHT0vb fFac5IDU6geo3p7ewXHNZimcEqHipD83f6/E0c/oImlzJ/THgDdskAhlrowqu6mYE0i0 OJJVXLYREHEOtE3a6JrXOe/aAqh447COCtNDZ+A98UsQAU8naoD62L/M+5Y2eH64NjWH JakQ9/fEplMlZOfbiIYXuVguaD1VSEZmniicXCf4BDMrmuV75AAQK6iggQWbBY4VGtLS jg==
Received: from nam10-dm6-obe.outbound.protection.outlook.com (mail-dm6nam10lp2101.outbound.protection.outlook.com [104.47.58.101]) by mx0a-00143702.pphosted.com (PPS) with ESMTPS id 3phv9pq2f1-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <dmarc@ietf.org>; Tue, 28 Mar 2023 12:36:43 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=b0eE+HPdlXvM5qW9BF+kkvNzoSJlTRCZdHS2MXOVDcHV/n68IhJfoVGOX8/IdOD6CEu7IE9qB+zO68B8kQIlGhwMoWDPg7oH8BCc8h3sV17a7hAIO6+zh+Zvcm22hJZz+ux9MDFbrsfbjAy7HR7aUcs5PIiLMGryOffN0ZAnfSatBE4xzROJ1u/5X8jgrR9z8etNXHmUysEBMznblYDKs9cFetUj8T6MLNvVb4hHBHBXAEv4yt4j8mdZC/1qwf4KKfPW1kUIMbZLa49fsNI+Q9wQqIQP7rMoOTVWP4oG0vQIvrqRzXZG5MGP2ZMSwkM9PBukCRTJv/ImB9BYZSZDhA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=BpjIANpVAxebUPLcTN1NwTuBv4noTcA6v3pR9Rx6fZ0=; b=PWr9LFW79M9Ur/tf6Nt0dUKI0utxJrwRgowYFyNVuChAlRMpRz7wQ3Ti9GsscRe/wcl7fb3fL59taqT7U6C7mOvF5BeVPAzIiKMP96IKR31RpgM7enJarrSbu/E1r7ty9oLjP1P6uYyyN0GfJezHnKaFB8i5FI25uZMlkwQEfx5rtT5rRBa1+tCVlQn77ptBe1saJX4LOjNUfOwefRC3G+32/+Bu4VXiWZxjsrLqCxt3T4DAYMvSeFzabqKAUJz0e4bFi8J+R3HjAbcdrdBBm9N0TBjirZgfZASYEKF9pMnznfoQNYEmU5+SE70uXwRZyZnTLtmvts7xVOfLchrdHA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=comcast.com; dmarc=pass action=none header.from=comcast.com; dkim=pass header.d=comcast.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=comcastcorp.onmicrosoft.com; s=selector1-comcastcorp-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=BpjIANpVAxebUPLcTN1NwTuBv4noTcA6v3pR9Rx6fZ0=; b=j/K5vjX+IvpNH6HI8dbLz+Fgh02Pftq8hmPnBZUOdmtG0nkIr/+htLWBkUIcvpmnVaMT53kNlTR2O5/4xj6ZFD14mPZKwIyDrCx7U8ZQevxjba2xH7l0/puFmFChwziV6iWZN9PqQH3mgidOVAJtDlMQhIA3neLwBI2Ae7fq2xE=
Received: from MN2PR11MB4351.namprd11.prod.outlook.com (2603:10b6:208:193::31) by CO6PR11MB5603.namprd11.prod.outlook.com (2603:10b6:5:35c::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6222.33; Tue, 28 Mar 2023 16:36:39 +0000
Received: from MN2PR11MB4351.namprd11.prod.outlook.com ([fe80::5acd:7431:27b0:8d40]) by MN2PR11MB4351.namprd11.prod.outlook.com ([fe80::5acd:7431:27b0:8d40%6]) with mapi id 15.20.6222.030; Tue, 28 Mar 2023 16:36:39 +0000
From: "Brotman, Alex" <Alex_Brotman@comcast.com>
To: "dmarc@ietf.org" <dmarc@ietf.org>
Thread-Topic: [dmarc-ietf] Proposed text for p=reject and indirect mail flows
Thread-Index: AQHZYU110RHIJKYq002iiG8E89Hj5a8QIRyAgAASqICAACX0AIAABVYAgAAEh1A=
Date: Tue, 28 Mar 2023 16:36:39 +0000
Message-ID: <MN2PR11MB435121B10F67BCD75DC99C2BF7889@MN2PR11MB4351.namprd11.prod.outlook.com>
References: <CALaySJ+NBg9vzqa0_t-sBf7EKXQ3A=DTyy-Vc7M-ZK9-vfJxmw@mail.gmail.com> <CAHej_8m7m29EiKUzarR1wBVyxfORfdcX_kgUz0-3uDiqoZ+i2A@mail.gmail.com> <CAHej_8nu8LZCEk2COCk6XUv9oPs2tP-SOZfUhKSqMxx8gBN8iA@mail.gmail.com> <3445610.T9FX6QkNB4@localhost>
In-Reply-To: <3445610.T9FX6QkNB4@localhost>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_15652fe2-2b59-4d95-925c-ee86d789ff67_ActionId=0bdcc5f8-3595-4afa-abdd-32cbe2742623; MSIP_Label_15652fe2-2b59-4d95-925c-ee86d789ff67_ContentBits=0; MSIP_Label_15652fe2-2b59-4d95-925c-ee86d789ff67_Enabled=true; MSIP_Label_15652fe2-2b59-4d95-925c-ee86d789ff67_Method=Standard; MSIP_Label_15652fe2-2b59-4d95-925c-ee86d789ff67_Name=Confidential (C); MSIP_Label_15652fe2-2b59-4d95-925c-ee86d789ff67_SetDate=2023-03-28T16:33:57Z; MSIP_Label_15652fe2-2b59-4d95-925c-ee86d789ff67_SiteId=906aefe9-76a7-4f65-b82d-5ec20775d5aa;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MN2PR11MB4351:EE_|CO6PR11MB5603:EE_
x-ms-office365-filtering-correlation-id: 4d588f4d-9539-45dd-19b3-08db2faa9b00
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: zxfxtJEL8Q0CWtJRS3/VnYAaugn1ORlJrWp6/+G2FcdRoItw6s947uyrmaSuXyo59lTxf7QS00mxbz1k3F5ZlJdZRxDDY9oOSc3Qo5WSNWqPzirAT0QtvV3fQytS6JcgA/ViqcaQMC+UfUvr1pbaGtP91Y0YLi3bslaWJkgtLdQtMsfIpD6uMiQLYeOCjqr2UinHUjpaxysjpQrCKZ7MC5uviHMPnI5SFXLS/y63W9lojxC6bX7D/bFClwM6lLQs+gCp0y2JOLDNLqH7/2OzuomKOXdu9/FCL+VKeeZK1c0B0pPgHxH5w/13LJ+A/r3XXWyjWWE/fSeVo6TQmQ3Txze/n0tiswLdLEgKWQN1xzsxjAQuUoBhep0BfSEMB2nN51uYJiSu/EFz4Q0mptMh8GhDhIRzzJcoRnyhyqFqGvSYLaJRSZL5lUDkW+7iCpT1PZ1XVqKO84o5X82Fw/bKIa44ZUEXIy7lieORWXY/ufMwL6XUFQiptFUvpKvTlULVcgebyJl+ZkLrIiHOhjla0RWouUO9v+Wel+5yTnPxSfaYiZnULMmmzuE8kKr+olqH97R3GUcKwZ7jsUnJ/kTeJi86ut5XGCfbdKD9MxjJRlE=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB4351.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(136003)(376002)(39860400002)(366004)(346002)(396003)(451199021)(41300700001)(8676002)(66446008)(64756008)(66476007)(66946007)(6916009)(66556008)(76116006)(186003)(2906002)(38070700005)(38100700002)(83380400001)(86362001)(82960400001)(122000001)(33656002)(5660300002)(55016003)(52536014)(8936002)(53546011)(478600001)(966005)(7696005)(71200400001)(316002)(9686003)(6506007); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: l6m2vNrVJ/l2JcKxCEID0Sueb71kJ76uuyvv1At/ZlJ0LpM8YqAIwkmrK/rrciaaWZrnhrZpjpiZHcnHJ5WaLc8HEPqc3FUsLL9uT1LF+hfjqKQE/PoU+F1W4UsgaXeIF4sXduGbvledweVW/j9SACkvvpFr7zsbq8BNamamAgtW9UdlXxkuaH6Gi2yvUKxwe9RiuxBg488wmwP6f+11PkkD7dbZhUhQXTL5hkCYGuNeV6S1kZtBaqkdWosXD6MIchZtl3kmQZ6F7t2xbsSj3l9iBwnQ+AzEc69rCZ8vemeoMCykLK4+UFoA4zLVv0eNBaU9azedgpbpMNWK7Yq9wEsQgDfp79BfQoAF7rMXMY2OAKRcXZfoUd44frwUmZgoH9TLgsHtiRCLHD0L066qGc0FSM6DpVFd1j1DAB2Trc4gMECqFzBoyqpnuzm6vfRjp6R7UNgWM+QTudYsebUAjJtgnuOvm4Msb4W/OkLHzKulCxgsueOs/wsAIf64wHUY0k62ujHmb/t2ypViUE46F+I0i8mchHKxbcB6jAXTctFVjTbf/Lqb0qiZ43XZngYLLOSh7GH9Whd87jlzJYYwR/zDHU9b8lKEVB/1skHJWo06ZvYClQ8KVfkK/uDzEljQThtpwP5e1Czemn/iYNeLnrx8y8Hmj7EqjMO3rFRJVumZQtgEmjx+bRXB6UqrVc56Ucx6krtd3xb9/qWRZXXn5IKLSGksdrpARxhhlwofP3L6FN0g2et/4YtyhvfQgVm9PIw20P32UFJXXaCmaIpeXHN+2VCm28D1hRjSxezgYJrZNlEb1fku+eLm2v3OwwGHdi6z2i97J2sqMogZ3F4e0P6dbNmn1zEei9TeEsQprRUh1Nat8MExKb+MIYrB3KNumctcdHbgCCKokD9vdeQAMAI2j2iG/HL23xMpRIeNGrSJ7+uPt3S5/I6M372Ttf3sOvTAwVo5k6XT3HkDfm2oJJmJUBz6FETUXUZjQ1FEMVUQ8ywe2SOfXQfukghdeg54Ozp9odaxNQG0p9j4dS6ai4NlNOhNN2OKPYSmC8QATj7ukZHKE00D/zyN2xFmR9jnC0noNURrpcKRXkO6DMESBGubsOWQ7IZo2dc2ew0uWldjLYPA6IkybxA0ZuvGagl5I3ZPEmtfKCUy43xazju+CxOENazuGxUVVbXcXAn78v8Oe5PNv+Wknab8InyK9bVIiUYSVGL5CVArGNgTFv8M/u7HPIloh+5W9tDNdURJlaIUoU5wyFQElz+rJRC1U9yYnXBFb8mL//PBL2jRO0rj6h55PiJOQIc2c2XVEtlGmmsCj9iF/P8bVCn4Gxu650rz8h34/GDOtMwXpzXplIx1oJMgwQu6mFQ+uUi9K86b87n8+/0w2XCq0isZRcVh2IXP9tC1oZJg4i4qop5IS1XvcbLP0lVn88zboLLU42W6uIxrw4o3C3mcKVVqlj9H/65N57Yd3ddjziUETxImIZ2OWBWgw39OdCyPbQ/4Dyx43jzN0+ycyN3kjSCbpG4d/RWCFIJBBPJy+eXkTlxilb56N9VOH+Q05kYc5ROhvc4236gcf+jGxGgZlt92VeGnJ9Y6ejKKBPDVaE8OTDFi0feDd2bL4p4IU+CjL3QZcOjiBsR8vCRSJczBshrYVembVuqJ
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: comcast.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR11MB4351.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 4d588f4d-9539-45dd-19b3-08db2faa9b00
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Mar 2023 16:36:39.4143 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 906aefe9-76a7-4f65-b82d-5ec20775d5aa
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: H6q2wmOYBS1pmhYt+5QdsmW7uyzKtzbV5qOSyuBc1pI0NvMxVhMp85e6ZAOelrdD8yVxpiYfSODgZR8wcTgg1bA70IPftgbdaDOjYsviilI=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO6PR11MB5603
X-Proofpoint-GUID: D2ighLUilSZF7bgx14eDl03i-MYu3sKo
X-Proofpoint-ORIG-GUID: D2ighLUilSZF7bgx14eDl03i-MYu3sKo
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.254,Aquarius:18.0.942,Hydra:6.0.573,FMLib:17.11.170.22 definitions=2023-03-24_11,2023-03-28_02,2023-02-09_01
X-Proofpoint-Spam-Reason: safe
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/dq8IrOsR_Yfuv-GaI1IcPdbYyKs>
Subject: Re: [dmarc-ietf] Proposed text for p=reject and indirect mail flows
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Mar 2023 16:36:48 -0000

Should it reference consumer-oriented domains instead? 

Users of comcast.net can't get an email account with out first being an ISP customer.  I don't believe the intent was to exclude them from the proposed language.  Similarly for a few other providers, and then there are explicit pay-for services like Fastmail, Tutanova, etc.  I would think they're in the same category?

--
Alex Brotman
Sr. Engineer, Anti-Abuse & Messaging Policy
Comcast

> -----Original Message-----
> From: dmarc <dmarc-bounces@ietf.org> On Behalf Of Scott Kitterman
> Sent: Tuesday, March 28, 2023 12:18 PM
> To: dmarc@ietf.org
> Subject: Re: [dmarc-ietf] Proposed text for p=reject and indirect mail flows
> 
> On Tuesday, March 28, 2023 11:58:40 AM EDT Todd Herr wrote:
> > Upon further reflection, I find myself liking Barry's proposed text
> > less, and instead propose the following:
> >
> > On Tue, Mar 28, 2023 at 9:42 AM Todd Herr <todd.herr@valimail.com> wrote:
> > > On 28 Mar 2023, at 17:15, Barry Leiba wrote:
> > >> > NEW
> > >> >
> > >> >    5.5.6.  Decide If and When to Update DMARC Policy
> > >> >
> > >> >    Once the Domain Owner is satisfied that it is properly
> > >> >    authenticating
> > >> >    all of its mail, then it is time to decide if it is appropriate to
> > >> >    change the p= value in its DMARC record to p=quarantine or p=reject.
> > >> >    Depending on its cadence for sending mail, it may take many months
> > >> >    of
> > >> >    consuming DMARC aggregate reports before a Domain Owner reaches
> the
> > >> >    point where it is sure that it is properly authenticating all of its
> > >> >    mail, and the decision on which p= value to use will depend on its
> > >> >    needs.
> > >> >
> > >> >    It is important to understand that many domains may never use
> > >> >    policies of “quarantine” or “reject”, and that these policies are
> > >> >    intended not as goals, but as policies available for use when they
> > >> >    are appropriate.  In particular, “reject” is not intended for
> > >> >    deployment in domains with users who send routine email, and its
> > >> >    deployment in such domains can disrupt indirect mail flows and cause
> > >> >    damage to operation of mailing lists and other forwarding services.
> > >> >    This is discussed in [RFC7960] and in Section 5.8, below.  The
> > >> >    “reject” policy is best reserved for domains that send only
> > >> >    transactional email that is not intended to be posted to mailing
> > >> >    lists.
> > > >
> > > >    To be explicitly clear: domains used for general-purpose email
> > > > MUST
> > > >
> > >> >    NOT deploy a DMARC policy of p=reject.
> >
> > NEW
> >
> > 5.5.6 Decide Whether to Update DMARC Policy
> >
> > Once the Domain Owner is satisfied that it is properly authenticating
> >
> > all of its mail, then it is time to decide if it is appropriate to
> >
> > change the p= value in its DMARC record to p=quarantine or p=reject.
> >
> > Depending on its cadence for sending mail, it may take many months
> >
> > of consuming DMARC aggregate reports before a Domain Owner reaches
> >
> > the point where it is sure that it is properly authenticating all
> >
> > of its mail, and the decision on which p= value to use will depend on
> > its needs.
> >
> > The policies "reject" and "quarantine" are more effective than "none"
> > for accomplishing the chief goal of DMARC, namely to stop the
> > exact-domain spoofing of the domain in the RFC5322.From header.
> > However, experience has shown that a policy of "reject" can result in
> > the disruption of indirect mail flows and cause damage to the
> > operation of mailing lists and other forwarding services; [@!RFC7960]
> > and [@!RFC8617] and Section 5.8, below, all discuss this topic and/or
> > possible strategies for addressing it.
> >
> > Because of these challenges, some domains, particularly those with
> > open signup capabilities, may prefer to remain at a policy of p=none.
> > This topic is discussed further in section 11.4 below.
> >
> > 11.4 Open Signup Domains and DMARC Policies
> >
> >
> > Certain domains with open signup capabilities, where anyone can
> > register an
> >
> > account and send mail, may not want to implement p=reject. An example
> > of such
> >
> > domains would be consumer mailbox providers that used to be known as
> > "freemail
> >
> > providers". Domains with no DMARC policy or a policy of p=none are
> > vulnerable
> >
> > to spoofing, but their users can send mail using these registered
> > email addresses
> >
> > from unrelated third party systems (such as "forward to a friend"
> > services) or participate
> >
> > in mailing lists without impediment. The security challenges that this
> > presents to the
> >
> > domain owner are left up to those systems that allow open registration
> > of users.
> 
> I don't understand the connection between DMARC policies and open signup
> domains?  What makes them in any way special relative to DMARC?
> 
> Scott K
> 
> 
> 
> _______________________________________________
> dmarc mailing list
> dmarc@ietf.org
> https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/dmarc__;!
> !CQl3mcHX2A!DOzdiSpU_A-
> KbSj6bpJZO_fnHiQ80eb3LTiQu2G9kcz185A1zp299yH6PyC4_Be61OT86Z4L1fyqtg
> Hk-xPY$