Re: [dmarc-ietf] UNCOL and Reversing modifications from mailing lists

John R Levine <johnl@taugh.com> Thu, 25 November 2021 18:17 UTC

Return-Path: <johnl@taugh.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 995F63A0D69 for <dmarc@ietfa.amsl.com>; Thu, 25 Nov 2021 10:17:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b=Jja3qKe5; dkim=pass (2048-bit key) header.d=taugh.com header.b=iiNeAiB8
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rJsOADJikTid for <dmarc@ietfa.amsl.com>; Thu, 25 Nov 2021 10:17:54 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EA1F63A0D66 for <dmarc@ietf.org>; Thu, 25 Nov 2021 10:17:53 -0800 (PST)
Received: (qmail 78473 invoked from network); 25 Nov 2021 18:17:50 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type; s=13286.619fd34e.k2111; bh=sVZ8hI85a1PwtgCUadKx2UEDuNx7xHKUNKzmn8neZBc=; b=Jja3qKe5l1/WKqpjSUUAhywxeGa84gtgaJQf8A31fCP//51eqZBJuS0xz6C+27mGeSrLIsgSHiI75kY9SGE2w12VChBS/itMAL2KQ9YciY13web9FtrPMRYxRDPw96yLMGrxc64+y4XipD8R+qxpESeYfr3a8VKLMwyN/RDiD1cfb6VA53H/dJkccsXNRV+YJmSjkZj+NU3DWkHIoieFz2gbH/iUO6boexB8O19RYU4zA+GkKuoCa1v4z6kyEma1Mki47YqZfDNe+pSLqk23aEh1gQRnIPub6zQgVC9N3gfI8VLQNlg2QNas4QX6EacVDVQZ+grmJZxJoci5DVeH6w==
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type; s=13286.619fd34e.k2111; bh=sVZ8hI85a1PwtgCUadKx2UEDuNx7xHKUNKzmn8neZBc=; b=iiNeAiB8697C+Xs2TpcW20uGE6sO2eo7cuTHSFKalglpwI9xX9pIz2wi0u6jCuFEQy/4ORM5klRkvFEgZzyk/065wdiuk4t5OSOzHHgySzDd6uqnX5j2+QrnJb7DN/fiksu3R7rYIhEwQeP7umh9P3HczxoRWNZxwPoCsFQZUCQzDujuAtzjpeC41QmP91piM3PdWoJ/Y0wxNklL65z0Jy3VmuBXuNDM8Wms18gsV8K9Pc4ySM4DbP6j5qMdYdDjpAFY2dO2zAjoUlGwipKqfnHKIeBakekfLmakIBVCqnZrN2uFR6mXTehbl9p7/67ybGrYe9Au/6lV6gGzhAG1LA==
Received: from ary.local ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.2 ECDHE-RSA AES-256-GCM AEAD) via TCP6; 25 Nov 2021 18:17:49 -0000
Received: by ary.local (Postfix, from userid 501) id 65E01308CE0D; Thu, 25 Nov 2021 13:17:49 -0500 (EST)
Received: from localhost (localhost [127.0.0.1]) by ary.local (Postfix) with ESMTP id 3F85A308CDEF; Thu, 25 Nov 2021 13:17:49 -0500 (EST)
Date: Thu, 25 Nov 2021 13:17:49 -0500
Message-ID: <587877aa-34a8-246e-fee6-038b85663766@taugh.com>
From: John R Levine <johnl@taugh.com>
To: Wei Chuang <weihaw@google.com>
Cc: dmarc@ietf.org
X-X-Sender: johnl@ary.local
In-Reply-To: <CAAFsWK2mqu3gZgdUWqT9gJ-5nSnnTyNCTyc7_RYYA7y8_xQrYQ@mail.gmail.com>
References: <CAAFsWK3qshdYDeeTOLPJEnk=gHFrRp==QJLvoG6RAYHau6Fy8g@mail.gmail.com> <20211123203406.73152307DA83@ary.qy> <CAAFsWK2mqu3gZgdUWqT9gJ-5nSnnTyNCTyc7_RYYA7y8_xQrYQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/sn1yP5KJdwZER-H7TSoU2EcVSrE>
Subject: Re: [dmarc-ietf] UNCOL and Reversing modifications from mailing lists
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Nov 2021 18:18:00 -0000

> Understood there is a lot of complexity in this space.  On the other hand
> there doesn't seem to be a complete solution to email authentication with
> regard to content modification by email forwarders.  The result is that
> DMARC adoption is low despite its benefit in preventing important classes
> of email impersonation.

Huh?  DMARC is nearly universal among commercial senders.  It's not widely 
adopted among mail systems with human users but it was never supposed to 
be.

Remember that AOL and Yahoo only turned on p=reject after they each had 
all their users' address books stolen, spammers were forging mail with 
addresses that the recipients knew, and they used DMARC to force the cost 
of their security failures on the rest of the Internet.

Regards,
John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
Please consider the environment before reading this e-mail. https://jl.ly