Re: [dmarc-ietf] Signaling MLMs

Benny Pedersen <me@junc.eu> Tue, 18 April 2023 23:14 UTC

Return-Path: <me@junc.eu>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80838C14CF1F for <dmarc@ietfa.amsl.com>; Tue, 18 Apr 2023 16:14:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=junc.eu
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SlLtWopSvzHS for <dmarc@ietfa.amsl.com>; Tue, 18 Apr 2023 16:14:16 -0700 (PDT)
Received: from mx.junc.eu (mx.junc.eu [172.104.150.56]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 51EFCC14CF15 for <dmarc@ietf.org>; Tue, 18 Apr 2023 16:14:15 -0700 (PDT)
Received: from localhost.junc.eu (localhost.junc.eu [127.0.0.1]) by mx.junc.eu (Postfix) with ESMTP id 0D6DC80E20 for <dmarc@ietf.org>; Wed, 19 Apr 2023 01:13:49 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junc.eu; i=@junc.eu; q=dns/txt; s=default; t=1681859629; h=from : subject : date : to : message-id; bh=VT+7ouivzRDHwaEBCLLFhOoQ5Q3BRYf1Y14Jv7e7R1A=; b=XFIcQbhw7VYzGgvKweAMjo6ITi8jNTWOud+AHOBJG42WLGNkrVOIh0MFEZYjfn5+t0FF2 YxlaVo4nLHaM8QzyXIMnQZzxDOT8avmH4hHLINFt75cEjk6fmJrJ/Hnz3XWzEfNR5+ToEUn 3kYfDeBFNDZ0NOq5il5+8/6zrlhfyMJPYt9DaD6vBRt/uuekzueWxGXipYrjD12AucCvvS/ RZZiKJPWT2qpYD7WmwfurlUxZrKz7w4iZWYFwyUWfVFaTS7Ihlj/a2exfhR1vjBV5IBdk0P 4+7TC8JuRIOGr5vX7IJ4O9/scf1vMVx11fSO6zT4ulugOPpb7tk+/DgqAsPQ==
ARC-Seal: i=1; cv=none; a=rsa-sha256; d=junc.eu; s=default; t=1681859629; b=qtTvIJYx8q0AD81SGxG5jD86Kd3ZdMKTCah/EcUHRROpc/tnYuJ1KpFeejBXSjbbInnWB /3AOHvCphDdcGJfAIt0fpDJLDQ7BSGZdWNQMqyeqiYl7gPXgzaQCIfmPY6YuzH7nAEUNNy0 4eU+4Xs2/hQoE+HDNa0dyatfBrFAovokudndFP1HWxoDvlxmhAcYDfHoRnZIMjT1gGJ+MuV qvXOYdM6AT8ehR1R9UskG8MqE2hVkJ3a+grCCsUEfKh5Idg+AjyBs5yCOn5VmOBbd4cnrW4 9iQjRHhtYALpHAoQ3ryLvmz5fOeGwcVpg4X/6Z2nIE6DLX8WuDkGfMWjXjRg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=junc.eu; s=default; t=1681859629; h=from : subject : date : to : message-id; bh=VT+7ouivzRDHwaEBCLLFhOoQ5Q3BRYf1Y14Jv7e7R1A=; b=C47tYxak7NE5qjfhAkIlKSVRZjjrsU5i4cb3OYT5tyjYO5SPV6exVmfHpQxGn681M5c6c b/Yvm47MyQDRyySrNYiGr9IQpRqwaI1KipRqGNoRpEE+CVRyEm+1FYN8AjvefrOmUmYFh6/ YVLedX5bShimMgpluLnxZYuqmSlsDI2te23yb1U2LTN2Pd5xVndps0lxt07gH0oazTUSJcy ko6Z8DBu2shp182lI7e0yMqOe1F9r5/MVEG0XsMUyxEMVTe39dLNrLwDKdujG/v0/t/HpN+ 11/JKkGVIDEo+FUdV5zGBx+RS7fgVwIB8+VYNgrZbMcE88BPoDnwKzoC7jMw==
ARC-Authentication-Results: i=1; localhost.junc.eu; iprev=pass
Authentication-Results: localhost.junc.eu;iprev=pass
Received: from localhost.junc.eu (localhost.junc.eu [127.0.0.1]) by mx.junc.eu (Postfix) with ESMTPSA id E3BD98012B for <dmarc@ietf.org>; Wed, 19 Apr 2023 01:13:48 +0200 (CEST)
MIME-Version: 1.0
Date: Wed, 19 Apr 2023 01:13:48 +0200
From: Benny Pedersen <me@junc.eu>
To: dmarc@ietf.org
In-Reply-To: <A8C8D8CA-47D5-40FC-B164-E8CB221B3F35@isdg.net>
References: <5DAE096A-B547-4569-A3C6-34ED9EC91B2D@isdg.net> <AA303EAF-76DA-4FAD-877D-C7B0143E21D3@marmot-tech.com> <643CB79E.7060309@isdg.net> <01ffe451b5f6e748cdcd295221f085e4@junc.eu> <D791743D-9E7F-4724-8181-44EF6148F5B3@isdg.net> <c19d02bdc96f8f016af430710ccb4247@junc.eu> <10c5dcb4-4eca-b6f4-6a76-29faf2700f76@tana.it> <A8C8D8CA-47D5-40FC-B164-E8CB221B3F35@isdg.net>
Message-ID: <0e65af20ba017692818670b156151e4f@junc.eu>
X-Sender: me@junc.eu
Organization: junc.eu
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/hBXDihaVnyCRph4TZ_mt9ubh6vw>
Subject: Re: [dmarc-ietf] Signaling MLMs
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Apr 2023 23:14:21 -0000

Hector Santos skrev den 2023-04-18 20:47:

> So your verifier see Benny’s as suspicious because of arc=fail?

it does imho not fail on my own arc ?

> Benny is telling the world “ietf.org [1] is authorize to resign on
> my behalf” via DNS.  No headers required.  No delayed learning
> necessary.

if all maillist did arc on incomming mails before mailman scrapled dkim 
then all will be good, only left is dmarc is not in all places tests arc 
results

its more waste that ietf add one more dkim signed keys, its not used at 
all in spamassassin unless one do welcomelist_from_dkim *@* ietf.org

> What more is needed?

more dokument on dkim fails, basicly dkim should not defined any reject 
reasons, eg it should not be possible to reject in opendkim at all, this 
should be in opendmarc policy, not just random chain rejects