Re: [dmarc-ietf] third party authorization, not, was non-mailing list

Jesse Thompson <jesse.thompson@wisc.edu> Thu, 20 August 2020 23:26 UTC

Return-Path: <jesse.thompson@wisc.edu>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 169153A1482 for <dmarc@ietfa.amsl.com>; Thu, 20 Aug 2020 16:26:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.048
X-Spam-Level:
X-Spam-Status: No, score=-3.048 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, MSGID_FROM_MTA_HEADER=0.001, NICE_REPLY_A=-0.949, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=wisc.edu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U1AxhukrpVIK for <dmarc@ietfa.amsl.com>; Thu, 20 Aug 2020 16:26:25 -0700 (PDT)
Received: from wmauth2.doit.wisc.edu (wmauth2.doit.wisc.edu [144.92.197.222]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 713AD3A0EC9 for <dmarc@ietf.org>; Thu, 20 Aug 2020 16:26:24 -0700 (PDT)
Received: from NAM04-BN3-obe.outbound.protection.outlook.com (mail-bn3nam04lp2055.outbound.protection.outlook.com [104.47.46.55]) by smtpauth2.wiscmail.wisc.edu (Oracle Communications Messaging Server 8.0.2.4.20190812 64bit (built Aug 12 2019)) with ESMTPS id <0QFD008SSYFZ74A0@smtpauth2.wiscmail.wisc.edu> for dmarc@ietf.org; Thu, 20 Aug 2020 18:26:23 -0500 (CDT)
X-Wisc-Env-From-B64: amVzc2UudGhvbXBzb25Ad2lzYy5lZHU=
X-Spam-PmxInfo: Server=avs-2, Version=6.4.7.2805085, Antispam-Engine: 2.7.2.2107409, Antispam-Data: 2020.8.20.232118, AntiVirus-Engine: 5.75.0, AntiVirus-Data: 2020.8.18.5750001, SenderIP=[104.47.46.55]
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ofsvHz0ulHfStITfkibsKUsznK+Tlo3lA66XA2/apmc060D2k6L+V61BHcHxt8/rjLh1Ta7Rhjba8W+yefhFlIdU49rerAbIbn5jv8HnhSGlr0TusUK70UAxIiK4seKhW3Y/tGKTTCCmrDHM0sFnY/+LQ2cfI2toXKffroMXjq1x32AQogqzNo9tKj3OaD6xK7MYppTZxXP7t4tfLVD7vsifQso66tyTTUl0FN1rQfR+fYegK+uaMnQCaXTgAi9djCw5VnSg7FI88DwI0o2oF/kkkpDIvPUUpK297OfZQwy4FFMtRKX0JJXVWoscBEsAlswyOPgIriJvEgIW0Km8kQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=MsGbvTi6YpxddeHEzrqvOiv97LUwJ8uwmYWrBUNxliw=; b=hrE4YXPWjHeO9Ri1vfYfV7laCGasg0NqcirbkZ09PuH4X+l26S9kp8uIUqdo36X0l41R30Z5xgeTIq8bL7dZzetcaIdyMw4B8roWt/CGZDn+aN9sBUDI+FZW3Oz/kT7E8Y4cSqqkf99Opz/G3yhURXqOyLz+7NVpZKJX9H8NYER5LiVojE9bwikipSIu0w2E6EuW5KoVNNJ4NmuEq/yUHmQb3vCe24L8Fe0obZU5oXczjSGV8C5d+ucfgAFSRRkjAYR2ThCtoEnjkOOee+hmc1N/QGHJu3ptxrUiwurAjzrhpXj8kSMaew+2omzeeVd8gnrh4qhGBSTIihnTY6OScw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=wisc.edu; dmarc=pass action=none header.from=wisc.edu; dkim=pass header.d=wisc.edu; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wisc.edu; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=MsGbvTi6YpxddeHEzrqvOiv97LUwJ8uwmYWrBUNxliw=; b=u9yz2329u5cVCHpapx/WpyZEuJuF/B0xdRXm+4bsCoPMa0K10DKWVwR/rE+8+IptstUWDvaE/tpaWMPl5ORNnKU0v/Mfd+nMJLSy5IaxpNjddJIaChTEDN+AeCta865Wc1lpRhBbbYIcqOfMc0jDYmdAVi5DYIh0wMwhAsPb3+0=
Received: from DM5PR0601MB3671.namprd06.prod.outlook.com (2603:10b6:4:7b::16) by DM6PR06MB3914.namprd06.prod.outlook.com (2603:10b6:5:8b::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3305.26; Thu, 20 Aug 2020 23:26:21 +0000
Received: from DM5PR0601MB3671.namprd06.prod.outlook.com ([fe80::8def:be24:c82c:8d50]) by DM5PR0601MB3671.namprd06.prod.outlook.com ([fe80::8def:be24:c82c:8d50%6]) with mapi id 15.20.3283.027; Thu, 20 Aug 2020 23:26:21 +0000
To: dmarc@ietf.org
References: <20200810172411.A13681E7CD8B@ary.local> <7e9326fc-ae27-d4bd-9f2b-9896da8320f1@dcrocker.net> <CAL0qLwacyBbJscEM_a4-nvugO0HBaSAdPqUPkfYYOOb++cOjQQ@mail.gmail.com> <5F396A77.3000109@isdg.net> <CAL0qLwYaqsU-U8yTcr5_cw0LmEomz8JbqUXuWNJ-bnkN6ceXyA@mail.gmail.com> <21110e7f-ea60-66d6-c2fb-65b716a049a9@tana.it> <CABuGu1qdZdXBSsAwCvk4244szskz6Pf9x83kRUGd8jHDafEMGQ@mail.gmail.com> <CAL0qLwYY8ZWq4k3wobOgSJSVnabsefPRiCtcVPrb_iF1JEUZag@mail.gmail.com> <5d4e48f86ca7479ab4889ddff57a2870@bayviewphysicians.com> <6c7c2ad9-8a7e-e44c-6b2f-559129f70a9d@tana.it> <CAL0qLwb-SG-dsNkiiGtYkUz_AwsZSd6f5cKFX07Kzme5iXoZJA@mail.gmail.com> <F37D57E3-C55B-41EB-B4BE-328E40F73E81@eudaemon.net> <CABa8R6sUoyaa8sMJVOCnUUuH=g--2PSNQ-eLhVuW5NorzcQvqA@mail.gmail.com>
From: Jesse Thompson <jesse.thompson@wisc.edu>
Message-id: <1988db12-7a72-6176-01aa-45848ad5683c@wisc.edu>
Date: Thu, 20 Aug 2020 18:26:19 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:78.0) Gecko/20100101 Thunderbird/78.1.1
In-reply-to: <CABa8R6sUoyaa8sMJVOCnUUuH=g--2PSNQ-eLhVuW5NorzcQvqA@mail.gmail.com>
Content-type: text/plain; charset="utf-8"
Content-language: en-US
Content-transfer-encoding: 7bit
X-ClientProxiedBy: CH2PR08CA0014.namprd08.prod.outlook.com (2603:10b6:610:5a::24) To DM5PR0601MB3671.namprd06.prod.outlook.com (2603:10b6:4:7b::16)
MIME-version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
Received: from [146.151.213.183] (146.151.213.183) by CH2PR08CA0014.namprd08.prod.outlook.com (2603:10b6:610:5a::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3305.24 via Frontend Transport; Thu, 20 Aug 2020 23:26:20 +0000
X-Originating-IP: [146.151.213.183]
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: b05584b0-6ed9-4493-b1ad-08d84560725f
X-MS-TrafficTypeDiagnostic: DM6PR06MB3914:
X-Microsoft-Antispam-PRVS: <DM6PR06MB3914524718855E8BEDE50062F65A0@DM6PR06MB3914.namprd06.prod.outlook.com>
X-MS-Oob-TLC-OOBClassifiers: OLM:7691;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: CLMZseHMH5mWOZRNUGhrscXhaw0849lNeWw4Yxs1JoFbtsAFbtrSFbV3sIqB3v4VYO36KJBFfEVJXOdXk2JO28VKjon/b8p/+Cvjdi+PO0AlZxDsJfS1jrN3ot85oYcgSZrg3BKJP6P7YlWs19KSf03bsXjwNPertaKKwtFKKDvvmHONHpUDpggcQOScxpoTPK1LQOc1wmP0JBc8bMsLspMBzM+cNX5qpgfC6SPh9K8Z8qkCxeijHxLABX+iUj9gJYgd7qIdCHkypEulEt8rZQT1c+Bg9hwZan7hoPfEiujvljReTIELTBSx520x2VSI9pBBNG5D1qis/OiS0PS78StdYS/484QCveoyuc06O+tII8bVFkbMA+pnKvHsjYvtSDTli4+GAHtzjgGYRUHNbfavk3J/x3+aCfRueK07Vh4p9QnyoOEV3Ft+j4bT9EsGgoq3/+wNuzv83dlyJpkJMgWgLWQqudRXZKMWIWI1NV8=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM5PR0601MB3671.namprd06.prod.outlook.com; PTR:; CAT:NONE; SFS:(39860400002)(366004)(136003)(396003)(346002)(376002)(2906002)(478600001)(316002)(31686004)(5660300002)(786003)(16576012)(4744005)(8936002)(6486002)(53546011)(31696002)(6706004)(8676002)(6916009)(26005)(66556008)(66476007)(66946007)(16526019)(44832011)(36756003)(2616005)(956004)(86362001)(75432002)(186003)(3940600001)(43740500002)(130980200001)(223123001); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData: eiXi8qBRbuX/RBJFpPRf9cPN1DDHMsngswr42mGfh+5KqByG2BgxPwoom50s841ygd4/F4wye7qgtXXjUfzFmDgcHnqC2kf/zVaxhLNE2DfebTHqhCapsrN1xkMd12xke2cty32EGCoQ10zL1+T1y8ZawOwIJntySmloCfOrh8p7PIIPAFqVSGzkSQ6PHHXlTub439/qlghcpv+zs4hTdRrU4uwotUOmh2og97tokliZiH+A+OF6AM6rAiW39Dmqj0ZegMKFFTOUdb+8CqgFcInH7+7uX0ODvVwl3tPUpBB7rw/phmUFNjSyn2rGHiZ2X05eFj5jNfOLxx+RUN1i6UQKVYYN3n9M1/6SIwwVbPJV/RDL8GDcv2dVHU2sgTGFunMsZVwGxqefraXnXhJnU8WdLh1WuWzu3HF/qei7ICyUibfjH63/eRGuF0XxvymjfCSOA623X1X+2JScwxM0PrQKVKkQHEkXlkUZF749av7O/SjfQbVmXiz8IXSdNjZaO0Ykrzn1SEVM+d+tmtuz0P8voVY9CeyePspqUHpXgu3tYEbnL/mKSZQy8bVBHu+aXnnKClo28leE4BzcgWqEqDt956uH6rX9tr+y62rUZXGNaW8rM/mnb5wtXSxg7LDOXTeaM1O1v7O5GWG1NrsNzA==
X-OriginatorOrg: wisc.edu
X-MS-Exchange-CrossTenant-Network-Message-Id: b05584b0-6ed9-4493-b1ad-08d84560725f
X-MS-Exchange-CrossTenant-AuthSource: DM5PR0601MB3671.namprd06.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Aug 2020 23:26:21.2315 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 2ca68321-0eda-4908-88b2-424a8cb4b0f9
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: spLiz3JCx+nKyr3fldZ1sV5zcdzOQfkrXkJFvORDLi1y5WkRNXf06UlTfe0lxSCzKx5oRGSHpq3Npdh5yHMuiw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR06MB3914
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/he-2OnUTx0ycWKp90Jd60U2pQoU>
Subject: Re: [dmarc-ietf] third party authorization, not, was non-mailing list
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Aug 2020 23:26:27 -0000

On 8/20/20 4:00 PM, blong=40google.com@dmarc.ietf.org wrote:
> Neither atps or spf include are really designed for large scale usage

That's my conclusion, as well.  I don't want to authorize every potential MLM to use all addresses in all of our domains cart blanch, even if I would otherwise trust them (e.g. their purported ARC results).

I *do* want to authorize our *own* MLM(s) to use our own domains for *internal* use... so I thought for a minute... maybe ATSP has merit for small scale usage, as an alternative to SPF include?  But no, I don't know if any MLM has a way to check to see if they are authorized via any mechanism, so they will continue to munge the From header for our DMARC-enabled domains anyway.  So, for this *internal* use case, maybe I'll just check the ARC result from the trusted MLM and replace the From header with the value of Reply-to/X-Original-From, and call it a day.

Jesse