Re: DMARC: perspectives from a listadmin of large open-source lists

"Robin H. Johnson" <robbat2@gentoo.org> Tue, 08 April 2014 05:16 UTC

Return-Path: <robbat2@gentoo.org>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4BE701A0122 for <ietf@ietfa.amsl.com>; Mon, 7 Apr 2014 22:16:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.911
X-Spam-Level:
X-Spam-Status: No, score=-6.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5mj-Z8oKOFAa for <ietf@ietfa.amsl.com>; Mon, 7 Apr 2014 22:16:31 -0700 (PDT)
Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) by ietfa.amsl.com (Postfix) with ESMTP id 3F7081A0121 for <ietf@ietf.org>; Mon, 7 Apr 2014 22:16:27 -0700 (PDT)
Received: from grubbs.orbis-terrarum.net (localhost [127.0.0.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id 3D38F33FFCB for <ietf@ietf.org>; Tue, 8 Apr 2014 05:16:21 +0000 (UTC)
Received: (qmail 11473 invoked by uid 10000); 8 Apr 2014 05:16:18 -0000
Date: Tue, 08 Apr 2014 05:16:18 +0000
From: "Robin H. Johnson" <robbat2@gentoo.org>
To: Sabahattin Gucukoglu <listsebby@me.com>
Subject: Re: DMARC: perspectives from a listadmin of large open-source lists
Message-ID: <robbat2-20140408T051158-246173691Z@orbis-terrarum.net>
References: <robbat2-20140408T031810-279861577Z@orbis-terrarum.net> <alpine.BSF.2.00.1404072357400.73388@joyce.lan> <E2D6EA08-144D-4DB3-ABFC-6F98AF3C588F@me.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <E2D6EA08-144D-4DB3-ABFC-6F98AF3C588F@me.com>
User-Agent: Mutt/1.5.21 (2010-09-15)
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf/cc39SlSbB-IifpNOQRlc6V0L4Us
X-Mailman-Approved-At: Tue, 08 Apr 2014 08:51:50 -0700
Cc: John Levine <johnl@taugh.com>, IETF general list <ietf@ietf.org>, "Robin H. Johnson" <robbat2@gentoo.org>, zwicky@yahoo-inc.com
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Apr 2014 05:16:35 -0000

On Tue, Apr 08, 2014 at 06:06:27AM +0100, Sabahattin Gucukoglu wrote:
> On 8 Apr 2014, at 05:21, John R Levine <johnl@taugh.com> wrote:
> > Mailing list apps can't "implement DMARC" other than by getting rid
> > of every feature that makes lists more functional than simple
> > forwarders. Given that we haven't done so for any of the previous
> > FUSSPs that didn't contemplate mailing lists, because those features
> > are useful to our users, it seems unlikely we'll do so now.
> Well,  Mailman 2.1.16 has the FROM_IS_LIST feature that "Fixes" the
> problem by putting the list address in the From: field.  That seems to
> work, except that you lose information (the sender's address) if the
> list wants to operate a policy of "Reply goes to list".  You can then
> assure that DKIM signatures are valid and set up SPF, etc.  This also
> has the effect of letting you operate through the various cloud email
> platforms that try to validate sender addresses.
This breaks the ability to reply directly to the sender when the
response should NOT be on the list, as well as the ability to put a
sender in a personal killfile.

And don't start on suggesting Reply-To instead, RFC 2822 already
noted that it should be set by the author, not the list software [1].

[1] http://marc.merlins.org/netrants/listreplyto.html List Reply-To
considered harmful.

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Infrastructure Lead
E-Mail     : robbat2@gentoo.org
GnuPG FP   : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85