Re: [spfbis] Fwd: RFC 7208 SPF - 4.6.4. DNS Lookup Limits increase

John R Levine <johnl@taugh.com> Mon, 25 April 2022 16:14 UTC

Return-Path: <johnl@taugh.com>
X-Original-To: spfbis@ietfa.amsl.com
Delivered-To: spfbis@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3E1E5C157B34 for <spfbis@ietfa.amsl.com>; Mon, 25 Apr 2022 09:14:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.2
X-Spam-Level:
X-Spam-Status: No, score=-0.2 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b=yJhmzlbI; dkim=pass (2048-bit key) header.d=taugh.com header.b=kN9HWscB
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fjZ1BLhCTSxq for <spfbis@ietfa.amsl.com>; Mon, 25 Apr 2022 09:14:11 -0700 (PDT)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C1BF8C14F612 for <spfbis@ietf.org>; Mon, 25 Apr 2022 09:14:07 -0700 (PDT)
Received: (qmail 51581 invoked from network); 25 Apr 2022 16:14:04 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type; s=c979.6266c8cc.k2204; bh=9PEFOUIYtnVbF2Q3rDfVpQpfvJHWmh0eLpG6vq0Thsw=; b=yJhmzlbIp6vWEfCvhAOAuGu9cn7HPjHcStsfrOwZjQRfjRUajRpGynmUPA2qZJwWb/ye6dD3WnwsFuIOyfVpWQUKGeSJR28iXfTdhZ868ri3Z0kH+chPvcxDq0ZMTQwNL1MZKwLmsKln69P/ELZida7mc1rFNcDbZxqp8RaAriFjOuys3Hv7FcnCT+Vcbp9dm1wolTyMO2jGAnsc6jI3ivIh/KHjj0A79fOr+VgggD5V0B32myZvgpvO/mma8lYLuxrVd4sGXkupOXQ1Pn2HLOIVRd19k+W/p5/qgJR2G8G3SQkIuJ/Gq/5MRaSjkMxUJ0FQbMbKKXsQduMfIS1kMQ==
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type; s=c979.6266c8cc.k2204; bh=9PEFOUIYtnVbF2Q3rDfVpQpfvJHWmh0eLpG6vq0Thsw=; b=kN9HWscBJLjkDTzXm86OHVokkcRsFy9w8ExTHUFtj/oxI/1x1M4KHEwYD1Zv8a09ruCxqBYepc5jggT3JifXmkNCg4j793uz7x5puq9Cyhw1Q7eI8B12RATiluQvwv3L/gx8mQrbRXhMimJAu5y+7Jex2yIsJHcnkzCYvIdiXDjX/q8XHnC/jRqjAd1iVogL1vYxUB5ZnTxS/2IN3i/YRyMvifitLtF5ZoiInlp6PqVJd0lbQpm9YRvqsWACwlbTBk2jk3S8nSvYWSrzfuiVNMhDPkZcmeTiesHDG8pfDgdz6QUSDKXXadMUKtAHG8ZNHgN/XNgOd4e8CLKoHZ81nQ==
Received: from ary.qy ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.3 ECDHE-RSA AES-256-GCM AEAD) via TCP6; 25 Apr 2022 16:14:04 -0000
Received: by ary.qy (Postfix, from userid 501) id 30DDA3ED3266; Mon, 25 Apr 2022 12:14:02 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1]) by ary.qy (Postfix) with ESMTP id 8D75E3ED3248; Mon, 25 Apr 2022 12:14:02 -0400 (EDT)
Date: Mon, 25 Apr 2022 12:14:02 -0400
Message-ID: <81e3e3fe-8651-e32b-1088-be5415fbbab5@taugh.com>
From: John R Levine <johnl@taugh.com>
To: Simon Gnieslaw <simon@gnieslaw.com>
Cc: spfbis@ietf.org
X-X-Sender: johnl@ary.qy
In-Reply-To: <CABi22cc3AQtrDyq=Lv_MoSkdDKQasqxFSON0H3WQRmFN8Qy0+Q@mail.gmail.com>
References: <CABi22cc9kTSti_HjyKO0XtdcGSXzjwUeqWs0bu_zoT9nBDTbnQ@mail.gmail.com> <20220424173704.303293E71A33@ary.qy> <CABi22cfx8-=zR4a3dttAcmqKz06FLNRdhay_1fUJdW4UoA4MTQ@mail.gmail.com> <bf5fcdd7-0695-9f95-0a88-3900a54100cc@taugh.com> <CABi22cc3AQtrDyq=Lv_MoSkdDKQasqxFSON0H3WQRmFN8Qy0+Q@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/spfbis/bIdOJimRNCQmW2V--rPHdx-Rr_I>
Subject: Re: [spfbis] Fwd: RFC 7208 SPF - 4.6.4. DNS Lookup Limits increase
X-BeenThere: spfbis@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: SPFbis discussion list <spfbis.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spfbis>, <mailto:spfbis-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spfbis/>
List-Post: <mailto:spfbis@ietf.org>
List-Help: <mailto:spfbis-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spfbis>, <mailto:spfbis-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Apr 2022 16:14:16 -0000

On Mon, 25 Apr 2022, Simon Gnieslaw wrote:
> What you just described for your DNS level is way beyond my skill level, I
> have no idea what you are talking about with ANAME and RRSIG, and I don't
> think that it would be an effective use of time for every sysadmin to learn
> this whole thing just to get past this limitation.

Makes sense.  So it sounds like you should round up some other sysadmins 
to find someone to develop better DNS tooling for you to use.

R's,
John

>> If you remember the type 99 SPF record introduced by RFC 4408, after a
>> decade approximately nobody had implemented it so we took it out of RFC
>> 7208.  I don't see why an updated lookup limit would be implemented any
>> faster.