Re: [dmarc-ietf] finer grained org domain

Tim Wicinski <tjw.ietf@gmail.com> Tue, 18 August 2020 16:43 UTC

Return-Path: <tjw.ietf@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9CADD3A0F53 for <dmarc@ietfa.amsl.com>; Tue, 18 Aug 2020 09:43:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VxYcuIRLhlNn for <dmarc@ietfa.amsl.com>; Tue, 18 Aug 2020 09:43:32 -0700 (PDT)
Received: from mail-oi1-x233.google.com (mail-oi1-x233.google.com [IPv6:2607:f8b0:4864:20::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 09AED3A0D02 for <dmarc@ietf.org>; Tue, 18 Aug 2020 09:43:31 -0700 (PDT)
Received: by mail-oi1-x233.google.com with SMTP id k4so18480272oik.2 for <dmarc@ietf.org>; Tue, 18 Aug 2020 09:43:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=fDJYK39dN+ZIWDZkmjtQ6jAtr6VsOQQDgx4lDQMR/8Q=; b=ZW6jDoaPgaHZnae5aSNOMYq/n8YcuWmOJdKwWNWIU647tcln6uxGD7S3JuOfPcbXJP FlVUqqofb7jWvtS27ObHXTbsndPoCPCBCxVI46Thi1OfH4DNoQ+WtqOmCeoE0oYX03dY 2KEMbY3mLmRsilpJilPgZGC6i1calOg9AuUWUv2zAfHxRcKds//794HD2VYd1JIxKFNB Y/VN0SquB/BLn25lcmAxyLbd++jBLjsjGIlVqACJObtLejCceWJ96YVKfWtUJ14KUULM 7/pr+EnnL0T+F7Gjy0bpeVRbqcV/Mpob4AHirqMIoQQhNUF0IpLf+OUNd8Lxoh0ZlFZe +l6Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=fDJYK39dN+ZIWDZkmjtQ6jAtr6VsOQQDgx4lDQMR/8Q=; b=XcSL0Q0DTOpT641YgY/Eze26Vzc3mOiMxHIf5848VHTFea/6IwqlnP21NL4vgpgoZJ G8DK3D3vYRCl+haJNxtjRru+MMgkhCt8qrtHIYtCjtde3oi4EI1n6K0TjTRLPsCtQxm6 h9F9tCrMHKHFYysdX0FT5h98odaD7pivcZzltzezIIhYftfvFV8poehUg/kgNURippe/ UhqTBe8p3Jrlw4RpManEzPJHBeYTbMCQQcPigQxOT3jS1c8uS129kFMQqHnWXhhNyOr6 TDoaTWRmkyKfv75g/g5lIAaJcxj/IlPgLfcLEMHXJZtN8/QvZ2VFKbtCkmPvjgRa6Dli MVBw==
X-Gm-Message-State: AOAM530FkxHFmKESItE0FqMSnzBuGpDdgtwMCei5LjDB8MalFauXfqBJ VSiE6TyNRBWrY0o7HCvRkl5EckNnnlSIVj8zycY=
X-Google-Smtp-Source: ABdhPJyVa5bdsaDETn4dWZ7CrJBojVnqS6mtLbuGqZvEF0NxN1Fg3IVTqmAokTBVdi8zDvByKhEe3XJghmkcUks4qaE=
X-Received: by 2002:aca:4a49:: with SMTP id x70mr591666oia.173.1597769011194; Tue, 18 Aug 2020 09:43:31 -0700 (PDT)
MIME-Version: 1.0
References: <20200808023259.1D07F1E60C2D@ary.qy> <977bbb4f-c393-0314-df72-17f342f2f975@wisc.edu> <BY5PR13MB29990BCF8E40BEB37AEEE4AAD75C0@BY5PR13MB2999.namprd13.prod.outlook.com> <585c222c-e288-5328-ea36-4d554234c838@taugh.com>
In-Reply-To: <585c222c-e288-5328-ea36-4d554234c838@taugh.com>
From: Tim Wicinski <tjw.ietf@gmail.com>
Date: Tue, 18 Aug 2020 12:43:20 -0400
Message-ID: <CADyWQ+EaOV7=+EYPNRa7Q7FGfdUBV2fKmpW1pwCM9O5rVaRM4g@mail.gmail.com>
To: John R Levine <johnl@taugh.com>
Cc: Autumn Tyr-Salvia <atyrsalvia@agari.com>, "dmarc@ietf.org" <dmarc@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000058712c05ad299648"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/mGQDV7qQdoqmnSZ1f4M4JlxH8K4>
Subject: Re: [dmarc-ietf] finer grained org domain
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Aug 2020 16:43:34 -0000

Speaking not as a chair...

I do think the tree walk deserves another look.   Years back when it was
brought up,
there was lots of talk of overloading resolvers. But as someone who spent
the past
several years looking at the DNS query data of good sized SaaS domains,
DMARC lookups
(or even DMARC NXDOMAINs) were on the low end of the spectrum.  Nowadays,
all web
properties point to CDNs, et al with 30 second TTLs.

tim


On Tue, Aug 18, 2020 at 12:39 PM John R Levine <johnl@taugh.com> wrote:

> On Tue, 18 Aug 2020, Autumn Tyr-Salvia wrote:
> > * Departments sending transactional email - move them to dedicated
> subdomains (this is where really complex institutions would benefit from
> walking the domain tree instead of always inheriting from the org domain)
> >
> > Is inheritance walking the domain tree a topic that has already been
> discussed ad nauseam? This seems like an interesting point of discussion,
> but I also haven't been participating on this list for ten years and don't
> want to get into it if this is a topic everyone is tired of or that has no
> possibility of change.
>
> We've spun our wheels a lot trying to figure out a better way to find the
> organizational domain than for everyone to download the Mozilla PSL, but
> not about changing it to a tree walk.
>
> If we could come up with a better way for domains to publish their own
> boundaries (see https://github.com/jrlevine/bound) then that would be
> easy.
>
> Regards,
> John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
> Please consider the environment before reading this e-mail. https://jl.ly
>
> _______________________________________________
> dmarc mailing list
> dmarc@ietf.org
> https://www.ietf.org/mailman/listinfo/dmarc
>