Re: [dmarc-ietf] Ticket #39 - remove p=quarantine

Douglas Foster <> Wed, 02 December 2020 00:16 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id BCFD53A0BE7 for <>; Tue, 1 Dec 2020 16:16:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.097
X-Spam-Status: No, score=-1.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id fKNkDk97V9pX for <>; Tue, 1 Dec 2020 16:16:21 -0800 (PST)
Received: from ( [IPv6:2607:f8b0:4864:20::e2a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 9CCDA3A0BE3 for <>; Tue, 1 Dec 2020 16:16:21 -0800 (PST)
Received: by with SMTP id q10so720985vsr.13 for <>; Tue, 01 Dec 2020 16:16:21 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=GKsZkpWBk5vNM+kpw1lTeH9oQtOEjyACYd5MMjatgM4=; b=fHHrrMUw8pIUrVAZXzEuXp91R+xWx70jWH46tOCA4IHlD88MSrgzpIV3dnWpTqQ0S2 ESFMV21ALPs5+/6gLVuw+dc61bnhhbGX13SZ0PFtNmpk2AfoO6X+Cs5fl8TpnAtn481k QaKqz4HTdurUkxt6RlzB+29suxaVFn6oC66myFIvH9jeIeAjNSIzy48E+71L48Xx3z3p KaFWDwR4k/2qZy8fc7vhiqTBqctg8EN75blC75564czLWlZ+4+YG0ZlNzCsShbHrEmPP ymI7VSdKobg/LPhLXm7xD4bnm68VoLi2DNCSOvqaNqHn/QZD5yLGC3MOQ+IpxAZ6Xyzf yO9g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=GKsZkpWBk5vNM+kpw1lTeH9oQtOEjyACYd5MMjatgM4=; b=sygJ4wwmXt8Lpf66/B5ZJmUzna7siuxQfebKYkYIrYHuAC2CJ8eWDofmstkbBE6YPG 2YNEs63YGdcfwWqk4miO9ydD8l4fE/zKdW23hoz0UcmhgeV3Zdiwp0GNUrq+pPRAxU6r foMgNdxdHNZUdCy6H5W3bsvH5Zdc34kHcTA5d20Bjo4BmYKL64hM3w5PAKnSwTsqoacE 8Ed2QLE7jRsWKv4Hfv5x/LCVpnxkbUBxKbAUVyCe6BC0qtl00ZeUtyPf2rZcIV9IMG+2 cj9EC9Dn98sVkYSHGqzUCaQadCqxNThyJufxAxqrKwKp+po80g1ND9bmxT4q8kL8zljd /7Cg==
X-Gm-Message-State: AOAM531WyPxbuNAmuxCiv6JqjovzxpF/HpGKvAuaL3RF6PRcOSC/ctzP AAbe8z2J/Hv+3zFQ477a5HzBA+fblAzef2ZYN3W7u9+g
X-Google-Smtp-Source: ABdhPJztjymaTjnrIFykwsLliqPW4Esx5PBTljXdrpLDwY7AdgJOIDGMAjG3c0qYkmG799Z3vP0PDaEHAL18XuXX8U0=
X-Received: by 2002:a67:2084:: with SMTP id g126mr5548729vsg.42.1606868180517; Tue, 01 Dec 2020 16:16:20 -0800 (PST)
MIME-Version: 1.0
References: <> <>
In-Reply-To: <>
From: Douglas Foster <>
Date: Tue, 1 Dec 2020 19:16:09 -0500
Message-ID: <>
Content-Type: multipart/alternative; boundary="00000000000019c5ea05b570272b"
Archived-At: <>
Subject: Re: [dmarc-ietf] Ticket #39 - remove p=quarantine
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 02 Dec 2020 00:16:26 -0000

I have always assumed that p=quarantine and pct<>100 were included to
provide political cover for "Nervous Nellies" who were afraid to enable

As an example, suppose Nellie makes the decision enable p=quarantine and
then goes badly:

If the recipient reports reject instead of quarantine, she can say:   "They
were not supposed to review it!  They did not follow instructions!"

If the recipient reports quarantine as requested, she can say:   "They
agreed to look at it.   We can assume that they will release it to the user
after seeing that the message is innocuous, but the quarantine disposition
decision is not shown in the DMARC reports."


As an email gateway administrator, what I reject and what I quarantine will
be determined by my confidence level in my system's risk assessment.
 Sender request will have nothing to do with it.

Pct<>100 is pretty much similar.   A sender can specify pct=20, but that
does not mean that I am going to allow spam into my system 80% of the time
simply to make the sender happy.   Nonetheless, p=quarantine and pct=20
might allow some organizations to move away from p=none, thinking that they
are taking "baby steps", and that is a good thing.

Disabling a deployed feature is a big deal.   Leaving it deployed is a
useful ruse to promote deployment.   I favor leaving both mechanisms in

Doug Foster

On Tue, Dec 1, 2020 at 6:56 PM Dave Crocker <> wrote:

> On 12/1/2020 3:17 PM, John R Levine wrote:
> > #39 proposes that we remove p=quarantine.  I propose we leave it in,
> > even if it
> > is not very useful, because trying to remove it would be too confusing.
> If it is confusing to remove it, it is probably confusing to keep it,
> albeit a different confusion.
> Since protocol specifications need to be precise in their semantics, so
> they are understood the same way by both producers and consumers, I
> suspect the issue, here, is a failure to adequately specify the meaning
> or a failure to specify something that is mutually useful and desired.
> So rather that be administratively expeditious for the working group
> process, I suggest this issue gets some meaningful discussion.  My email
> archive indicates it hasn't gotten any discussion at all.
> Just waving this through because it will be a hassle to deal with it
> invites random differences in its use, and that is death to
> interoperability.
> d/
> --
> Dave Crocker
> 408.329.0791
> Volunteer, Silicon Valley Chapter
> American Red Cross
> _______________________________________________
> dmarc mailing list