Re: [dmarc-ietf] Call for Adoption: DMARC Use of the RFC5322.Sender Header Field

Dotzero <dotzero@gmail.com> Mon, 17 August 2020 14:47 UTC

Return-Path: <dotzero@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 800FB3A0E76 for <dmarc@ietfa.amsl.com>; Mon, 17 Aug 2020 07:47:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aPxcEtNlh_qk for <dmarc@ietfa.amsl.com>; Mon, 17 Aug 2020 07:47:06 -0700 (PDT)
Received: from mail-qk1-x729.google.com (mail-qk1-x729.google.com [IPv6:2607:f8b0:4864:20::729]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 330E93A0E73 for <dmarc@ietf.org>; Mon, 17 Aug 2020 07:47:06 -0700 (PDT)
Received: by mail-qk1-x729.google.com with SMTP id d14so15136319qke.13 for <dmarc@ietf.org>; Mon, 17 Aug 2020 07:47:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=g7edJ1XK6VkppeoH3zxbCRjsvbNerdY6vMDTFCwDzmc=; b=YsYaE8Ju1GUc2rForlejsQGggANQ8bnj5dfWR6LPUJRDN1sq0lkUmTOvSwx9qUB4o0 Cz9Nksc4xjf7UiaQHDbgBCK6LpN/5KNkX+3X9VVJs/0i5OoPxpm/AeN9NEcSw0HFoj9g 9gk4Bifiedcf9dTCkYkt95dWU5vA/1awga1YXZErQEAbw3zVktn8wbGrTP7anqbXN+2+ zBBUXyvcBqrBYZPXZpnj8D5D0ehv/qqkNmaP1YZBhkfaRF+GWy6KM17WQ6CEB62XEW+h WSGUzU08l3l93z8JXt89fi8EyFQi8eVSIub3YD9Cm+niGrUEZT6fmzy8JBVJIIiuUS9E z0aQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=g7edJ1XK6VkppeoH3zxbCRjsvbNerdY6vMDTFCwDzmc=; b=JWB/KZetRyG63lbxSLEmMbBENEkfReV3ellDXM7bA1Sh5A76ONBIVA2Q4arOPBXrYm lAGnglm1TWw/XE/W/yKNeiF1VUyEoUM2s5nURy/Zj07vjjvjL25s4NmP7OTfLQeCtxHy tMh40jv0kK7MDTmRvAGM1u8NZmjXn6Tfrr40QTZ3JxH60M6Z8iRD8MQGydtCyY0MUIa+ y0ImYi+EHuDWbzfLd/qkz9Ac6o7YcrV5ey5UIOa7jITwdVCdNHqkhohFJ1oQW2VRSJ2m B4zYW10Bh9bjvzwPFNQNPThAjg1RZlZsVKji/11wyorde2/HVXUX15GIDIAhZde/jXD4 YbeA==
X-Gm-Message-State: AOAM530dmIU7cCVTyfPlBA9IhGMGfBFwPCFSVwGw2nAgnN1JlJT6ClFT lk8VTZJl0vbvg4guQ4t21kWqO19T0oZir4dXI0H1679q
X-Google-Smtp-Source: ABdhPJzi7TeMBghsnpun8szkPmgRYeRJ/f12Hpj/RaTftFhkz8CJssaVRCQG0JCgBtvip0UvN3w26EMkiqisVwdGCIY=
X-Received: by 2002:a37:9f0a:: with SMTP id i10mr13668817qke.368.1597675625369; Mon, 17 Aug 2020 07:47:05 -0700 (PDT)
MIME-Version: 1.0
References: <CAJ4XoYcFbh8-nAxjxzzRgUahFfhcgcZQ2yMF2ewv_-DgUmhL=g@mail.gmail.com> <20200814164237.313071E971DB@ary.local> <CAJ4XoYeqj_5mpZu1PZP4rNfrWRyC5gC-2dfK7oX9xQHiR24QeA@mail.gmail.com> <085c6a5f-5451-ae8c-4873-133673ba1754@tana.it> <CAL0qLwaVUi9QtV4zcCwncuy4N3YPwsGZPzFfd1q19io79UG2VQ@mail.gmail.com> <c1844590-4b12-9763-21c5-6ac5b730321b@tana.it> <6358f3da-806b-f4eb-b9a0-8ee8ce4121d7@dcrocker.net> <4e549ca6-6047-6ff2-325c-fe8d7247e157@tana.it> <c972e0af-b589-1780-47b3-8cb2a2024ec2@dcrocker.net> <13a0ed72-2c5a-8ba6-84ab-b857e29403f1@tana.it> <b5935bde-e8-78ef-ed17-90a1d730aa9d@taugh.com> <8CCCBF0C-8651-4298-BB29-457381655D1D@wordtothewise.com> <beba49bc-e599-4f5b-72ad-2328938af9da@tana.it> <7FC8E909-1A13-4682-B3D8-EAD76F2B02BB@wordtothewise.com> <CAJ4XoYcx=doEfrN2M=X8OZQF0Nq+AFRLYqTgrsr1zMFSJVwziw@mail.gmail.com> <7C25FA42-6C6B-45B9-8476-B74F2455EDDC@wordtothewise.com> <CAJ4XoYfyxQTV_gFAJVPNW8V6s4aRCJBUTeJM89i5yiV_r9N9DQ@mail.gmail.com> <15597ef0-9057-b21e-8d4a-88bd777216c7@dcrocker.net>
In-Reply-To: <15597ef0-9057-b21e-8d4a-88bd777216c7@dcrocker.net>
From: Dotzero <dotzero@gmail.com>
Date: Mon, 17 Aug 2020 10:46:54 -0400
Message-ID: <CAJ4XoYeVYQcBrdDdZbrNgzfzBXDBy6kqa8f_xtGrqkuJMn3Sqw@mail.gmail.com>
To: Dave CROCKER <dcrocker@bbiw.net>
Cc: IETF DMARC WG <dmarc@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000001dd6e505ad13d8fe"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/gCYgdPs7iRaMhSDssINWbDMSw-g>
Subject: Re: [dmarc-ietf] Call for Adoption: DMARC Use of the RFC5322.Sender Header Field
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Aug 2020 14:47:08 -0000

On Mon, Aug 17, 2020 at 10:37 AM Dave Crocker <dhc@dcrocker.net> wrote:

> On 8/17/2020 7:33 AM, Dotzero wrote:
>
> DMARC fixes one thing and one thing only, direct domain abuse.
>
>
> It does no such thing.  Domains can still be 'directly' abused in all
> sorts of ways that DMARC does not affect.
>

Mea Culpa. You are correct that it only does so in the context of SPF and
DKIM validation which protects rfc5322 From field domains and aligned
rfc5321 Mail From domains (SPF).

> <rant>
>
> A continuing and in my view fundamental problem with discussion in this
> space is the lack of careful and precise language when talking about
> actions and effects.
>
> </rant>
>
> So...
>
> DMARC fixes abuse of rfc5322.From field domains.
>
> THAT is the only thing it does.
>
See above. I was even more specific than you were in terms of what DMARC
does.

> And it does it at the expense of breaking some legitimate uses.
>
Only when it is used in domains where there are individual user accounts
and not (only) transactional mail uses. If I use a hammer (no pun intended)
to pound in a screw, it doesn't make it the right tool for the job.

Michael Hammer (Inaccurately referred to by you as Herr Hammer)