[dmarc-ietf] Dmarcbis way forward

Francesca Palombini <francesca.palombini@ericsson.com> Mon, 23 October 2023 08:03 UTC

Return-Path: <francesca.palombini@ericsson.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A6D8CC14CF1E; Mon, 23 Oct 2023 01:03:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.109
X-Spam-Level:
X-Spam-Status: No, score=-7.109 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EwUljdVBMtif; Mon, 23 Oct 2023 01:03:55 -0700 (PDT)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-db3eur04on2050.outbound.protection.outlook.com [40.107.6.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 106E9C14CEFD; Mon, 23 Oct 2023 01:03:54 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=nBUAgKuJ1BupbWcnOwv+sQYoZM1M4l+csDhQf0aMw8WggMoD6Q2GfRZfutz3gsn2oJPsNU9I8w8R0tN/R3UHC+ESInJtP8j5XMDHXZAkXdd4KhSyvLhH3A4skev3QYUH9CTpmoCyxN8WLdpukCxBunAmFlAY73/N+OXRq2OAhBK54JiaJwzTNVHEWYM26sPIiCmkHfex8ZXFi5P05WKzGkaxe2vjByrati4pnp1a31Z0fas4Fy+mFs8e92ldsgaXNwP48FAPZnuXXA8so57032Ha8NANuHDpd+SxeQZyTGKolHoY5ZMsTQ6EtXAO/YGd6m988++5WiNlXsWmN1HLfQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=nClzKIfsOJ1lgHhsRSk5HgqsJSRBwjlB8rmnUFYrdYs=; b=ChKXTFqZwQdPzaidBiWUg2tSTSg1AEWPE/MnAIvL0T7ujjYuoduYoyPRcAWquAY+snN/3Kv/9rnExWdNgO79ZeG0fNMQPzBBBsBJtcAgmucAP1t9liPt3J1PTcCesaJLylXQ1x3tm0MpE9xAWjbrTxh92Hh95xF/U7IWWciP3a96sltPAdT6N02xPmksM1Z+K0mmSM1sLYYUxB9QCOBswhT10rIntSDJg5WHi92efjNtm7XCQg+HwbiTfWi2OmiMnD+pGy7wnZRYfLTMpt5V+CQwlYLEI+qEuvva2akq/qKwZfpdegDkYmeqf6YLu/tfjFP31/MIQWVKVeibsJaymA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=nClzKIfsOJ1lgHhsRSk5HgqsJSRBwjlB8rmnUFYrdYs=; b=RnsEMkWa6yth2ZM956a6SjMBYygPxbu8HA4n/aQ9CLRidhbrXSnp6ffiCdxjfIUbk2G+kzPKm5Lpv7iclqO24RmAQUhggK3KjAkDF0r1+ITGdk5zk9t5S80OSMV0ud7jDn6+oVA7HqsO1ShhrJ+8D0cQSjfBbn2MFn9LIbedT4k=
Received: from AS1PR07MB8616.eurprd07.prod.outlook.com (2603:10a6:20b:474::16) by PAXPR07MB8385.eurprd07.prod.outlook.com (2603:10a6:102:225::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6907.33; Mon, 23 Oct 2023 08:03:51 +0000
Received: from AS1PR07MB8616.eurprd07.prod.outlook.com ([fe80::5798:9ac9:c04e:e3e3]) by AS1PR07MB8616.eurprd07.prod.outlook.com ([fe80::5798:9ac9:c04e:e3e3%2]) with mapi id 15.20.6907.028; Mon, 23 Oct 2023 08:03:51 +0000
From: Francesca Palombini <francesca.palombini@ericsson.com>
To: "dmarc@ietf.org" <dmarc@ietf.org>
CC: "dmarc-chairs@ietf.org" <dmarc-chairs@ietf.org>, "art-ads@ietf.org" <art-ads@ietf.org>
Thread-Topic: Dmarcbis way forward
Thread-Index: AQHaBYZRZzLyphVvVUSWLyWIKB+pQg==
Date: Mon, 23 Oct 2023 08:03:36 +0000
Message-ID: <AS1PR07MB861698DF23A8C6CBCC93983B98D8A@AS1PR07MB8616.eurprd07.prod.outlook.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: AS1PR07MB8616:EE_|PAXPR07MB8385:EE_
x-ms-office365-filtering-correlation-id: 749d55c7-1c76-4c99-f5c5-08dbd39e9824
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Xq+gOv57xYJoHDJczoJJjMHcIn23Bdg4lhQ5YQ9Q/4svxn90wgdFpRJK5d0ey1jsYtKhiPB58pk4vxov/fSY8V9g5ErDUnuxr+f/2w2sIfWKdIMeoWD1qAjxugOwDjJ3GiCRkRmV9iZnUsQqRuCHx9P6fZDti78S2V3Wcb3WiYnzX/rET/n9anc65SMnNObS2uXr1XzgPkBaCf04lqgzNjqVO+9bQA9R2kvn7AlRRD52j3Fb1hGk3B37rYHeE5DQi7EyKLusuaxMgYvQbJyBgi4arkyNT/a5ddJ/73oL41wzCgxSq5bNxqrzn4Jax8KPCquPlztl784tfVsgk2o4iKYVldSI+D42gAMyNyW9YYXJ+9x0qzP9ipVgO0t8T2aUhoFKS+xuHQQRjCklrCIY8Be2Ywyj0d1NpwNOIGFa6uRglL0+cc9SW7v6pFQFEIjaPSNyEY1S+BnAuRMxA3+p5bEnp65TgF5lmUJeyo1cWsJrQHNZ0mfCAh+xc+SVoeAgjqRq3xwrXjnZouJshdxaY1R1sNWkmpPdinuKlaftLL6JlTy9fhpMkPbDGmejpwTFjJ78Bg7IlhAKZSm/RHS7TdnKhlNpiyxkqUn37Qz6J2EWqKiyhm+RXqUyWSoMLKpKGhR2+L5lePAj7qBwm+ogCq2q1wDPV8cFWiPXqjdK4Kfs9mV8emJ5kPXH+IvZRIiY
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AS1PR07MB8616.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376002)(136003)(39860400002)(366004)(346002)(396003)(230922051799003)(186009)(1800799009)(64100799003)(451199024)(38070700009)(38100700002)(166002)(2906002)(55016003)(44832011)(41300700001)(7116003)(5660300002)(86362001)(52536014)(450100002)(4326008)(8676002)(8936002)(33656002)(7696005)(6506007)(6666004)(71200400001)(478600001)(3480700007)(122000001)(82960400001)(66476007)(76116006)(316002)(6916009)(66946007)(64756008)(66446008)(66556008)(54906003)(83380400001)(966005)(9686003); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: yudpBs7psHi1Ti2OUQoiPh0Ww4sDvcPXM5agBetbDTZPTzZ6q+ax3HHnur/Fafr+JNDwgHeExzAtKhM/6KM00jsGO+OwjiDOShgDZXLtmt72Q6JPewt1vmychqPhR1O3YWyGgjDZoeHuFvudzipIPZWE1iwly+oWUN1LFfGYv5vxRDlYf8dn5ZglcWmP5ZAOoQYC8mxMBuJMe06DXFM+gVwExoGt06lbV7lEJBxQV6I2mw04ETXIX+y+uKC/JPJ0Mo5Rfy2wTNAd8pAqU8nzRVMb+oJblyiXUfh/Ac3dKwnPx9aIzwdPEfTpQbiU0U0fWq78kG81NbihAaf29mC/9KGi4r0YDgmDqrhBGww9AsnVaC5SDK+vUZcxTolQkZ8SJhnuBvAM9EaEF3qzHwAw4mBuZ5S/13yLWFd6XW0ho+wGU1cRdE2KrCBOolpEOTrl3IZ67bA3BR2tG7cYbedovCPVxDeGVj8gRPuDSVpoUPP0UgTiKA6l541j2xVXMvfoFvORn1bRCryF6z17bMX4nupQ//f/d7o7MZPWe7D/1WXVAgqOtppQWJNTYJILjG7fXwUDiJSKVpqkNLjH9RP7gtJR0uunI9Ad83+KO+b153K9c56cRCWLJUygy141yeVRi9OdNBpmrNlX2Y/oKL9wyGKm+TPmIaIcSakzE4qHNAdvStYqeLJCwcN1hBr4yyNDG1+EXSpLPwtYnJkyzGioRsK5tplXzMx5zlpq8EZ+D2iXZaGvCFmIl9mTG6K7O5YK7RtbbiHQs9HghqzH2Y1OOdZ8T2278C8TohgzQkkoDcTxzGsO+YGc3koDuEGCiK8HaoyahvlYSKztFOPSONe8yfnTqGOt8473g660fe/gtlzchkUxelkwtc01UAn/8iijWsNskcZNNCLGvY2KgpOebLm54HIPDSu/IRUE0V1o3+wywcozxfymnhf0RuHBSUnZy+z1i8hYE7rVHlmbC5m2gL4idNujTOysmtlZ6a5pEdDbQNiuJcZ9wGli+2ste2caWeeEUVll1lPe0ElK8fMekWlh9ESglT5GJWw2QJeoYvTYil7HGiUa3QfzMWZ6yL8LE21Ej6OiRvw+GZGsob5zfpNBl+I4IMgZxAGx9FnPv1CzYCwa3UAQHmlaehP91K49dx4NIkKnwD4Emogg+rSkdN4epienWP4/6/tf8ecEJ0JFvTFRGv5+69/oGm7b5eNNfl21u9wg4E2oj9HSn2OC41b81Km9e9M1DqylLU8E14v3OeOOPVs9UEHDOx00WjbilaZVgaAZYLi7ltiplz2+o//PMZ9IOA8HdfwtpuuM7N9E433400GihnrErTUn+js1Ir1oeTophn1FWB3OIbPuG9NyFTpYZtwtkGlnZmJHahxydp3CFv2HuLeIsRLfq4CE7IUjpUkSi2PRKPH+kAUI24wwwBmwIrRu7tn8Nspo+4cthcYRRfKqqKweNtv5N8jlUlSwt6zwO0yUHRBB8MARcvsT6Cp4X36o36Ja772V+7BxUsbsffOU01FtUPeP+j2yntYA4vKmq+dVTC+Z05q/cLGSq6+pZJA5YudHwdwsG7IxwEYTEKMySazhi7lBdRuWZqgpGOnQNi33TrIj1p2iKTqKaNXRbBp1If5UvDuLbgoBK4/pBoEpKDeNkPEhNNFMqQIuUwEOvazh+hZCUpajONKSLsU03Q7f1M/ECZ+hpBU=
Content-Type: multipart/alternative; boundary="_000_AS1PR07MB861698DF23A8C6CBCC93983B98D8AAS1PR07MB8616eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AS1PR07MB8616.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 749d55c7-1c76-4c99-f5c5-08dbd39e9824
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Oct 2023 08:03:51.3314 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: MwFi4BzDCPKaEcoRKoV2rhI57k2df//tYUOeFamoLU8ODx3mDS5d4KolMaxhOrXx4FEtIMvMFr1h7coXBPYsACuEU/qyY49B+gd7lP/KDXJjeGS2XuE62Mu1MyrcUrjm
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PAXPR07MB8385
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/ink9cG3bono8O2Vif_ibiexad0A>
Subject: [dmarc-ietf] Dmarcbis way forward
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Oct 2023 08:03:59 -0000

I have been asked by Murray to assist with a consensus evaluation on the discussion that has been going on for a while about the dmarcbis document and how to move forward.

I have made an attempt to evaluate consensus on the topic, trying to look at it from a complete outsider’s point of view and trying not to let my personal opinion bias my assessment. This is a summary of that evaluation. It is based on several threads in the mailing list: [1], [2], [3] and recordings of the IETF 117 wg meeting [4]. I also tried to pay attention to chronology of comments, because some people have expressed different support for different proposals, in which case I consider the latest email I can find as the person’s latest opinion.
Although that was mentioned, I believe there is no consensus to move the document status to Informational. I believe there is a rough consensus that a change needs to be made in the text to include stronger requirements admonishing operators against deploying DMARC in a way that causes disruption. The mails go in many directions, but the most contentious point I could identify is if there ought to be some normative MUST NOT or SHOULD NOT text. Many people have suggested text (thank you!). I believe the ones with more tractions are Scott’s MUST NOT proposal [2] and Barry’s SHOULD NOT proposal [3]. I believe most people who’d prefer just descriptive text have stated that they can live with the SHOULD NOT text, but they have stronger objections towards the MUST NOT text. There also a number of people who strongly believe MUST NOT is the way to go, but these people have not objected strongly to Barry’s latest proposed text in the mailing list (although they have made their preference clear during the meeting [4]). As a consequence, I believe there is a stronger (very rough) consensus for going with Barry’s SHOULD NOT text. I also believe there is consensus to add some non-normative explanatory text (be it in the interoperability or security consideration sections, or both) around it.
I suggest the authors and the working group start with Berry’s text and fine-tune the details around it.
In particular, as another AD that might have to ballot on this document, I suggest that you pay particular attention to the text around the SHOULD NOT, as also Murray suggested in [5]. I have often blocked documents with the following text: “If SHOULD is used, then it must be accompanied by at least one of: (1) A general description of the character of the exceptions and/or in what areas exceptions are likely to arise.  Examples are fine but, except in plausible and rare cases, not enumerated lists. (2) A statement about what should be done, or what the considerations are, if the "SHOULD" requirement is not met. (3) A statement about why it is not a MUST.”.
I appreciate everybody’s patience and constructive discussion.
Francesca, ART AD
[1]: https://mailarchive.ietf.org/arch/msg/dmarc/Z2hoBQLfacWdxALzx4urhKv-Z-Y/
[2]: https://mailarchive.ietf.org/arch/msg/dmarc/wvuuggXnpT-8sMU49q3Xn9_BjHs/
[3]: https://mailarchive.ietf.org/arch/msg/dmarc/k6zxrKDepif26uWr0DeNdCK1xx4/
[4]: https://www.youtube.com/watch?v=8O28ShKGRAU
[5]: https://mailarchive.ietf.org/arch/msg/dmarc/Ld-VObjtihm5uWd9liVzMouQ1sY/