[dmarc-ietf] Re: Discussion Thread for Issue 155

Tero Kivinen <kivinen@iki.fi> Fri, 25 October 2024 23:35 UTC

Return-Path: <kivinen@iki.fi>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A1EBDC151992 for <dmarc@ietfa.amsl.com>; Fri, 25 Oct 2024 16:35:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=iki.fi
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id COVf205EMB3l for <dmarc@ietfa.amsl.com>; Fri, 25 Oct 2024 16:35:02 -0700 (PDT)
Received: from meesny.iki.fi (meesny.iki.fi [195.140.195.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 56A03C1519A4 for <dmarc@ietf.org>; Fri, 25 Oct 2024 16:35:01 -0700 (PDT)
Received: from fireball.acr.fi (fireball.acr.fi [83.145.195.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: kivinen@iki.fi) by meesny.iki.fi (Postfix) with ESMTPSA id 4XZzf82QvmzyQK; Sat, 26 Oct 2024 02:34:56 +0300 (EEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=iki.fi; s=meesny; t=1729899298; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=qIUnVgr/blIG8Tt0+4wb5RvQEfVvsEWH/Sak/6o74Jk=; b=MBuoc5sdgUjHw4oZBhq6F5iKAHcsVBB1rzK+u7GE113m1uN8GzdKt8+/rvVUYxPv2VFyxG Gku9zWtzaWgFJxTBMqZCX6oXRwzZ3/4S+ZnT1YIA0VeIP8PQf0AOhkueGIIQucK+oP1C8g +Zz/GImSZ+hJi32O8XXnFQaQr6bLbDY=
ARC-Seal: i=1; s=meesny; d=iki.fi; t=1729899298; a=rsa-sha256; cv=none; b=H2Fq0mM3fHFNDoZoB0eZ5CIu0uQlC4/s9/tz7QE6j/02jOyuEKc7QRUdADsA/pqBAZ07AB WqfhbirNiy99+QK63+1uzcPF18UZKuudEUZfvO60CWiJB98V7QzbzYYNVk/eZ0BHkXsHPb gn6UgF2m8zH2s4XZbqy6x1t1fKoyNwM=
ARC-Authentication-Results: i=1; ORIGINATING; auth=pass smtp.auth=kivinen@iki.fi smtp.mailfrom=kivinen@iki.fi
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=iki.fi; s=meesny; t=1729899298; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=qIUnVgr/blIG8Tt0+4wb5RvQEfVvsEWH/Sak/6o74Jk=; b=BjWaPOTlHtdR2yPANhsK+igKC/HejbO5t89sl/uCU47hnLagNji5x9oAht0TqdS3NG0m69 OgGW667H9bHRnOB4KEtmyrL1KgcLIveiw3IbLSamBvPiHPKDNPrUtEchsgjwusncmv77Ia iBQZO6MEakAHEigjqNJZgVpfR0kVX80=
Received: by fireball.acr.fi (Postfix, from userid 15204) id 2951325C1327; Sat, 26 Oct 2024 02:34:54 +0300 (EEST)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Message-ID: <26396.11038.80744.934855@fireball.acr.fi>
Date: Sat, 26 Oct 2024 02:34:54 +0300
From: Tero Kivinen <kivinen@iki.fi>
To: John R Levine <johnl@taugh.com>
In-Reply-To: <084985fb-5bcd-1acf-e73c-358690f49f3a@taugh.com>
References: <CAHej_8=Gs0XURT4UVrKxxfc45BtVDmPRgGT9rvxDHBbzbd-0bw@mail.gmail.com> <CAL0qLwY0PjxkTAkSEwB_s6KgAODFAB8z665wKY-pLJ16UT8oXA@mail.gmail.com> <21B7963C-1CBC-4017-98D7-77749FDA6B3E@bluepopcorn.net> <CAL0qLwYqrf=G2ws1e05EUS2JSaU=KyhcXF8OUJ5aXV4nvKXVFA@mail.gmail.com> <bbfe0737-b8af-412c-9d98-a31c29b8c175@crash.com> <CAL0qLwYqMyUtFcmTFs8HOwjPnt_0VN2UxpuwXbYwpOc5JgtfgQ@mail.gmail.com> <20241024221344.26C84A326945@ary.qy> <df9b2e0f-f7cb-4346-a2d0-0f55be92e8f2@tana.it> <084985fb-5bcd-1acf-e73c-358690f49f3a@taugh.com>
X-Mailer: VM 8.2.0b under 26.3 (x86_64--netbsd)
X-Edit-Time: 5 min
X-Total-Time: 4 min
Message-ID-Hash: 2R2TTQLZSIWECFHDBXDUKJ4IDE7DYBFV
X-Message-ID-Hash: 2R2TTQLZSIWECFHDBXDUKJ4IDE7DYBFV
X-MailFrom: kivinen@iki.fi
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dmarc.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Alessandro Vesely <vesely@tana.it>, dmarc@ietf.org, Murray Kucherawy <superuser@gmail.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [dmarc-ietf] Re: Discussion Thread for Issue 155
List-Id: "Domain-based Message Authentication, Reporting, and Compliance (DMARC)" <dmarc.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/eQGBvFQHnMTTjWZLHxUNt2_OjlA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Owner: <mailto:dmarc-owner@ietf.org>
List-Post: <mailto:dmarc@ietf.org>
List-Subscribe: <mailto:dmarc-join@ietf.org>
List-Unsubscribe: <mailto:dmarc-leave@ietf.org>

John R Levine writes:
> > That way a receiver has to manage a list of forwarding recipes for each user.
> 
> Surely it is obvious why this sort of thing does not scale.

Why not?

I have less than half a dozen places that forward emails to me. Then I
have perhaps about few dozen mailing list domains where I have joined.
The list of my forwarding domains has been stable for quite long time
(years), I do not even remember when new indirect mail flow was
created for me from new domains (I have joined new IETF mailing lists,
but they are using same forwarding domain still).

Mail recipient systems already do much more heavy processing for every
single email I receive, doing one list lookup to see which ARC
forwarders to trust is much cheaper than some of those spam filterings
it does.

So why do you think this does not scale?

There will not ever be global trusted ARC signers list, as that list
is different for each user, thus trying to make it global would be
pointless. There is per final mailbox user list but that only will
have few dozen entries. 
-- 
kivinen@iki.fi