Re: [dmarc-ietf] Header Rewriting

Laura Atkins <laura@wordtothewise.com> Wed, 06 January 2021 15:20 UTC

Return-Path: <laura@wordtothewise.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5D5083A0E8D for <dmarc@ietfa.amsl.com>; Wed, 6 Jan 2021 07:20:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=wordtothewise.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xqhegZchprN2 for <dmarc@ietfa.amsl.com>; Wed, 6 Jan 2021 07:20:11 -0800 (PST)
Received: from mail.wordtothewise.com (mail.wordtothewise.com [104.225.223.158]) by ietfa.amsl.com (Postfix) with ESMTP id EA5C23A0E8A for <dmarc@ietf.org>; Wed, 6 Jan 2021 07:20:10 -0800 (PST)
Received: from [192.168.0.227] (unknown [37.228.231.27]) by mail.wordtothewise.com (Postfix) with ESMTPSA id E72F69F149 for <dmarc@ietf.org>; Wed, 6 Jan 2021 07:20:09 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=wordtothewise.com; s=aardvark; t=1609946410; bh=SrfF/2vBxPYrZqkLOz2glqEioc4DhToE02ANY4ailSU=; h=From:Subject:Date:References:To:In-Reply-To:From; b=gftGLlHZzey8Xx4LmTrBg5qRTns2XZhEjh/Uq27zvVzS8kd+fMnT7thFWNmMtYup3 /BrFKVsya/5X9EUiMrxK4c/TBopwj17WTnbN3vFT8XkQvbUgf9G3U9XmPPsz7w/R48 1rB2TjjoEEnb505YwuCqlxkAu12xvSvshoNwX5So=
From: Laura Atkins <laura@wordtothewise.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_F01B7247-634E-4FE0-93BC-8667B4E515EC"
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.120.23.2.4\))
Date: Wed, 06 Jan 2021 15:20:08 +0000
References: <20210104174623.2545154CFF9F@ary.qy> <FD45F9FC-46B0-40A9-ADC6-DDD7650D62F2@bluepopcorn.net> <ae77d9f-6f63-16ca-903a-7cb463a7b58d@taugh.com> <CABuGu1o2t7WaEOh+nsx3_MRUGgGHqKHzQ9302FM9-HL0GxvJvA@mail.gmail.com> <f15c8f53-8075-99a1-83c7-f687200e6a94@gmail.com> <f640ee95-ba0a-6aa7-1a14-2af1db151e27@mtcc.com> <050e8614-c088-a165-a733-35c5eee52eed@gmail.com> <ECBF25D9-F05C-4DE9-AD97-6D4D01B01B57@wordtothewise.com> <CAH48ZfyTUNg2_PnHFHEtZFemfvBgWBMpGLphGTL=3mRvD9o==w@mail.gmail.com> <D3A51087-6E1A-465F-89CD-63172E8075D4@wordtothewise.com> <b4c0e4fd-30a3-bacb-742f-ae611109af84@mtcc.com>
To: IETF DMARC WG <dmarc@ietf.org>
In-Reply-To: <b4c0e4fd-30a3-bacb-742f-ae611109af84@mtcc.com>
Message-Id: <B705BC02-824F-4F83-B0D9-EF9349410A56@wordtothewise.com>
X-Mailer: Apple Mail (2.3608.120.23.2.4)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/jKcL3Yoq7PyxkY9RtbLQRS1raXw>
Subject: Re: [dmarc-ietf] Header Rewriting
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Jan 2021 15:20:12 -0000


> On 6 Jan 2021, at 15:14, Michael Thomas <mike@mtcc.com> wrote:
> 
> 
> On 1/6/21 4:52 AM, Laura Atkins wrote:
>> 
>> Most users may know who constantcontact are or mailchimp because they advertise widely. Some might have heard of GoDaddy but do you know what the company name of the GoDaddy ESP is? I don’t off the top of my head.
> 
> An extremely dubious assertion. Source? I barely know who they are and could not name them unless I saw their names first.


That was actually my point. One you decided to clipp out of the email you’re replying to. Having these companies rewrite the 5322.from address to domains they control does not increase security. It is an end run around the small amount of protection DMARC offers and is a bad idea. 

laura 

-- 
Having an Email Crisis?  We can help! 800 823-9674 

Laura Atkins
Word to the Wise
laura@wordtothewise.com
(650) 437-0741		

Email Delivery Blog: https://wordtothewise.com/blog