Re: [dmarc-ietf] Doing a tree walk rather than PSL lookup

Alessandro Vesely <vesely@tana.it> Wed, 25 November 2020 08:08 UTC

Return-Path: <vesely@tana.it>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2B5C43A11FA for <dmarc@ietfa.amsl.com>; Wed, 25 Nov 2020 00:08:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.111
X-Spam-Level:
X-Spam-Status: No, score=-2.111 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, T_FILL_THIS_FORM_SHORT=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1152-bit key) header.d=tana.it
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8ZVbgOulAvsl for <dmarc@ietfa.amsl.com>; Wed, 25 Nov 2020 00:08:40 -0800 (PST)
Received: from wmail.tana.it (wmail.tana.it [62.94.243.226]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 48CDF3A11F8 for <dmarc@ietf.org>; Wed, 25 Nov 2020 00:08:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tana.it; s=delta; t=1606291716; bh=mb4vtFHr88aikGFotHAVuvKfPErrd3yf36Ztdr/bZUA=; l=926; h=To:References:From:Date:In-Reply-To; b=BplDGpdDW7Sb4BNVIAw4JmERsS+Jf7y7kOhsQctSTo/1ml1+T39usV+s7RdZ9mQCY fWL49UQTG88zI9x7nBg6nSV69WfELtnGIfca95bggolLAz56DZLxRc351sbjhqRDZO M5Ey6RPdB3fCpFT+V8dlA5z69n5vzqhaK4lblFiX2hh0nwpkcotiJEFbwZte8
Authentication-Results: tana.it; auth=pass (details omitted)
Original-From: Alessandro Vesely <vesely@tana.it>
Received: from [172.25.197.111] (pcale.tana [172.25.197.111]) (AUTH: CRAM-MD5 uXDGrn@SYT0/k, TLS: TLS1.3, 128bits, ECDHE_RSA_AES_128_GCM_SHA256) by wmail.tana.it with ESMTPSA id 00000000005DC07E.000000005FBE1104.00001678; Wed, 25 Nov 2020 09:08:36 +0100
To: John R Levine <johnl@taugh.com>, dmarc@ietf.org
References: <20201124170351.C430227DFEBF@ary.qy> <36f4f840-0911-56f5-185b-3f60166eab47@tana.it> <e5d3a3bc-8a44-7b33-bdda-ca457ff3e984@taugh.com>
From: Alessandro Vesely <vesely@tana.it>
Message-ID: <12b892a9-372a-3627-3183-cd318a368a78@tana.it>
Date: Wed, 25 Nov 2020 09:08:36 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.12.0
MIME-Version: 1.0
In-Reply-To: <e5d3a3bc-8a44-7b33-bdda-ca457ff3e984@taugh.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/yz9_2dJDaP5ZW-Xtb47hxZ5M1hA>
Subject: Re: [dmarc-ietf] Doing a tree walk rather than PSL lookup
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Nov 2020 08:08:43 -0000

On Tue 24/Nov/2020 20:29:11 +0100 John R Levine wrote:
> 
>> "Holy Roman Empire"
> 
> Organizations, typically universities, where the nominal organization tree and 
> the actual control are different.  The PSL isn't useful because the party that 
> controls their Org domain often doesn't control lower parts of the DNS tree.


The PSL takes care of particular cases, listing suffixes like cloudfront.net or 
various flavors of amazonaws.com, which officially look like any other 2nd 
level domain, but actually host independent organizations.  Those entries are 
commented with the names and email addresses of the principal who submitted 
them.  In their own words:

     In addition, owners of privately-registered domains who themselves issue
     subdomains to mutually-untrusting parties may wish to be added to the
     PRIVATE section of the list.
                         https://github.com/publicsuffix/list/wiki/Guidelines

Best
Ale
--