[Mailsec] Re: SMTP headers in DATA block?

John Levine <johnl@taugh.com> Fri, 06 June 2025 19:00 UTC

Return-Path: <johnl@iecc.com>
X-Original-To: mailsec@mail2.ietf.org
Delivered-To: mailsec@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id AAC1C31E7502 for <mailsec@mail2.ietf.org>; Fri, 6 Jun 2025 12:00:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.4
X-Spam-Level:
X-Spam-Status: No, score=-4.4 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b="FhFup90g"; dkim=pass (2048-bit key) header.d=taugh.com header.b="ThFvqkMV"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aJ3fy7KMDCDS for <mailsec@mail2.ietf.org>; Fri, 6 Jun 2025 12:00:51 -0700 (PDT)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 0D0F731E74F9 for <mailsec@ietf.org>; Fri, 6 Jun 2025 12:00:50 -0700 (PDT)
Received: (qmail 38695 invoked from network); 6 Jun 2025 19:00:50 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:content-transfer-encoding:cleverness; s=970968433ae2.k2506; t=1749236440; x=1749582040; bh=BoCTtOe0Am8OHi6I5LRCwYSWUPl1QiZgPio/cytg3bk=; b=FhFup90ghLPXWmitZ3Mw31hmBxQ8qRc8lQtZk4IgGamLRpGVRQB+zxPF0p+IYrbYW5Bl5R7xIzodPmTXj5BluLpo7sazCXUUHLcLB6ybMIoiM+m6LK7WCWGO8lh3gTDxMHmY+Ak6Jp+Cs0asZYKsOIih0j/JJ4PucYdb9Y0tCexpq3caSnfuWzKkl1JB6UKYlNHbq92l6BFhFyLmujaFtSLCywL+ExAlCOF4VoO9VrK4Ma4rXM2vW/rZPZu9EO+JTfuCOLSCGJlvt2txDz7C+yMSwcleukP037y/OOpnUW9MzdwGCPvzZKPtaJKteRKGT2eikWohnOk4KlthI/tgZw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:content-transfer-encoding:cleverness; s=970968433ae2.k2506; bh=BoCTtOe0Am8OHi6I5LRCwYSWUPl1QiZgPio/cytg3bk=; b=ThFvqkMVy4WIWB/CzQPENapgre/PO+GPzEDaGPkqe9Cs35zs3/F9gxcunsggxTe59vNCE8W2fCa6SAeiyMuaGIPsDhwuUKJWuiaZ5MOXAw/cUwgAXCRrJH0gkTmyOP+sni81gm7c5UDpZO7j+P8SJtCcSIjOqE5ah9EF7xxllZXOHVZ5XKojJjCPyYarJZymZ2gVIpRNVymqmNC7w6cQQT4+WRhYq1qCDyfl0pED+peWBdiVtbK0pJuwG4yTU5Kx1izi6K1xbcPby2JqdS4Oix87ppy12uj9dPKXysQLm7KBujHf8Uui2zErg5LzupjM27W0KgGa9UPU8N6Rnfy+qA==
Received: from ary.local ([IPv6:2001:470:1f07:1126:0:78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126:0:78:696d:6170]) with ESMTPS (TLS1.3 ECDHE-RSA CHACHA20-POLY1305 AEAD) via TCP6; 06 Jun 2025 19:00:50 -0000
Received: by ary.local (Postfix, from userid 501) id 41F79CD32E87; Fri, 6 Jun 2025 12:00:48 -0700 (PDT)
Date: Fri, 06 Jun 2025 12:00:48 -0700
Message-Id: <20250606190049.41F79CD32E87@ary.local>
From: John Levine <johnl@taugh.com>
To: mailsec@ietf.org
In-Reply-To: <5223991.nocEyzAEji@workstation.vm.ideapad.lan>
Organization: Taughannock Networks
References: <5223991.nocEyzAEji@workstation.vm.ideapad.lan>
X-Headerized: yes
Cleverness: minimal
Mime-Version: 1.0
Content-type: text/plain; charset="utf-8"
Content-transfer-encoding: 8bit
Message-ID-Hash: 42HFHHYBU72XGWEICHAROJB47C5JNZ5M
X-Message-ID-Hash: 42HFHHYBU72XGWEICHAROJB47C5JNZ5M
X-MailFrom: johnl@iecc.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: ietf@nixmagic.com
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Mailsec] Re: SMTP headers in DATA block?
List-Id: Email Security Issues <mailsec.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/mailsec/6B3sxCYK7DDFftECKtshHKd9pLU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mailsec>
List-Help: <mailto:mailsec-request@ietf.org?subject=help>
List-Owner: <mailto:mailsec-owner@ietf.org>
List-Post: <mailto:mailsec@ietf.org>
List-Subscribe: <mailto:mailsec-join@ietf.org>
List-Unsubscribe: <mailto:mailsec-leave@ietf.org>

It appears that Michael De Roover  <ietf@nixmagic.com> said:
>I would like to address this issue in an IETF standards document, that 
>streamlines MAIL FROM and RCPT TO from the SMTP level, with the From and To 
>from the DATA field. 

Sorry, but no.  There are good reasons that SMTP separated the envelope from
the header 45 years ago and those reasons are as valid now as they ever were.
Mailing lists like this one put an envelope address that points back to the
list manager so they can handle bounces.  If an MUA showed that rather than
the author's address in the From: header, that would just be confusing and
annoying.

As someone else noted, DMARC provides a way to say you want the envelope
and header addresses to match, and our experience with has been decidedly
mixed.

MDAs often add Return-Path: and Delivered-To: headers to log what the envelope
addresses were, but I have never seen an MUA that shows them other than for
debugging "show all headers".

R's,
John

PS:

Some MUAs apparently already show messages such as the one below.
>
>Caution: This email originated from outside the organization. Do not click 
>links or open attachments unless you recognize the sender and know the content 
>is safe.
>
>This is promising, because it means that there's already existing code that 
>modifies the DATA field on transmission from MTA/MDA to the MUA. 

I am reasonably sure text like that is inserted by the MDA or a filtering proxy
and the MUA just shows what's in the message.