Re: WG Review: Domain-based Message Authentication, Reporting & Conformance (dmarc)

Hector Santos <hsantos@isdg.net> Fri, 18 July 2014 16:41 UTC

Return-Path: <hsantos@isdg.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 868F11AC0D2 for <ietf@ietfa.amsl.com>; Fri, 18 Jul 2014 09:41:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.079
X-Spam-Level:
X-Spam-Status: No, score=-101.079 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HELO_MISMATCH_NET=0.611, HOST_MISMATCH_COM=0.311, HTML_MESSAGE=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CO4ihC8G3V_u for <ietf@ietfa.amsl.com>; Fri, 18 Jul 2014 09:41:55 -0700 (PDT)
Received: from mail.catinthebox.net (secure.winserver.com [208.247.131.9]) by ietfa.amsl.com (Postfix) with ESMTP id 10AA21A0301 for <ietf@ietf.org>; Fri, 18 Jul 2014 09:41:54 -0700 (PDT)
DKIM-Signature: v=1; d=isdg.net; s=tms1; a=rsa-sha1; c=simple/relaxed; l=3021; t=1405701705; h=Received:Received: Message-Id:From:Subject:Date:To:Organization:List-ID; bh=qvpu1YZ zkdvdMx9IcT1oMNKXpDw=; b=JI0hOzr5sPJia1ELk+oxchiI+W9kjg+6wklfTm/ ESCCTg8FUkmAuZI8gP/mjpXqzl0Z9dGWaVsjZZijaYnfylrvsJ8G3OCJM3Tqlw4K HZLCItGXSsnduLNWqp4F/c30xC85pkW7cRK/Vd4KHlqavcNMOtw1vAxF1f3bra/m C+kA=
Received: by winserver.com (Wildcat! SMTP Router v7.0.454.4) for ietf@ietf.org; Fri, 18 Jul 2014 12:41:45 -0400
Received: from [192.168.1.162] (99-72-160-212.lightspeed.miamfl.sbcglobal.net [99.72.160.212]) by winserver.com (Wildcat! SMTP v7.0.454.4) with ESMTP id 886822410.3783.3316; Fri, 18 Jul 2014 12:41:43 -0400
References: <6C10A695-8F29-4D94-8CF5-FAA0E975A33E@gmail.com> <20140717195712.11D7B1ADAE@ld9781.wdf.sap.corp> <CAL0qLwYZPO9L9e7MHA6zP5vcTbQEJmwCSonLdMeQiOw4CUoiFw@mail.gmail.com>
Mime-Version: 1.0 (1.0)
In-Reply-To: <CAL0qLwYZPO9L9e7MHA6zP5vcTbQEJmwCSonLdMeQiOw4CUoiFw@mail.gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail-857CE8B8-F60E-456B-8F06-5EFAFDCC10B0"
Content-Transfer-Encoding: 7bit
Message-Id: <04ABCD2D-C913-4E8F-B84B-1CD989A42874@isdg.net>
X-Mailer: iPad Mail (11B651)
From: Hector Santos <hsantos@isdg.net>
Subject: Re: WG Review: Domain-based Message Authentication, Reporting & Conformance (dmarc)
Date: Fri, 18 Jul 2014 12:41:41 -0400
To: "Murray S. Kucherawy" <superuser@gmail.com>
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf/NpM8Tv8JUo3_bqicNBlVzXHj-Ag
Cc: ietf <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Jul 2014 16:41:57 -0000

> On Jul 17, 2014, at 5:24 PM, "Murray S. Kucherawy" <superuser@gmail.com> wrote:
> 
>> On Thu, Jul 17, 2014 at 12:57 PM, Martin Rex <mrex@sap.com> wrote:
>> 
>> And DMARC reporting needs to be killed.
> 
> Could you elaborate on why?  I only ask because some operators think the reporting is actually the more valuable thing DMARC has to offer, and you seem to have different information.

Beside it becoming a potential source for abuse, i.e. DoS, in general, once the proof of concepts are achieved, reporting becomes a wasteful, redundant high overhead part of the process.  This is why it I believe DMARC should be split into two; reporting and policy handling or reporting made an option for implementors who might only interested in the policy handling enforcement aspect and do not wish to be sending out reports -- we already know it works.

--
Hector Santos
http://www.santronics.com