Re: [Tools-discuss] SPF rejection of mail to chairs

Jim Fenton <fenton@bluepopcorn.net> Sat, 29 February 2020 20:04 UTC

Return-Path: <fenton@bluepopcorn.net>
X-Original-To: tools-discuss@ietfa.amsl.com
Delivered-To: tools-discuss@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 572643A1253 for <tools-discuss@ietfa.amsl.com>; Sat, 29 Feb 2020 12:04:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=bluepopcorn.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oouN6TzxIjUM for <tools-discuss@ietfa.amsl.com>; Sat, 29 Feb 2020 12:04:46 -0800 (PST)
Received: from v2.bluepopcorn.net (v2.bluepopcorn.net [IPv6:2607:f2f8:a994::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9D4113A1252 for <tools-discuss@ietf.org>; Sat, 29 Feb 2020 12:04:46 -0800 (PST)
Received: from steel.local ([IPv6:2601:647:4300:2290:dde4:bdf4:df3e:8c13]) (authenticated bits=0) by v2.bluepopcorn.net (8.14.4/8.14.4/Debian-8+deb8u2) with ESMTP id 01TK4iao021034 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO); Sat, 29 Feb 2020 12:04:45 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=bluepopcorn.net; s=supersize; t=1583006686; bh=CgpIbiYx1GrOaEg42SOCOTiwaLm3OEgCzI5+Ma8drz4=; h=Subject:To:Cc:References:From:Date:In-Reply-To; b=s+y5VWDfUBiJwvVmbYGJqGcPbo0UOSoHyXVbk0Ccb/Kn8tU4Vo28ORCquZq4wXCgM ia2+oht/aNJNQsRaZfhXJZqLRd1kYoVd05EyhrKKEPVY+uBfsn+2Xb0Yow7nqiYRwF DIEHQwJZpxFN5YU95MRoTwHKoT2LYykmaNUT4ARU=
To: Carsten Bormann <cabo@tzi.org>
Cc: tools-discuss@ietf.org
References: <RT-Ticket-282330@www.ietf.org/rt> <20191121040335.A47AD120944@ietfa.amsl.com> <253406B7-7911-4971-9ED5-D836606D3B6A@tzi.org> <rt-4.4.2-17081-1574310971-201.282330-4-0@www.ietf.org/rt> <CABL0ig51Bfs5w94vnZnTBQaQ+mC5+Vjett61Cs1d0sc_DpFsXA@mail.gmail.com> <9898.1574329972@dooku.sandelman.ca> <A7C5D382-FDE4-4EB7-9463-FB2E0884920C@tzi.org> <96dbab15-2b11-4114-8ad0-690047430d68@nostrum.com> <DB2BE9AA-1018-44B0-B926-AF27427B4577@tzi.org> <0C8935E8-7693-4FAE-85DF-33408D297F15@tzi.org> <7f34680e-4fe8-cf17-a0e9-d3696d509a6f@nostrum.com> <73AA0A63-585C-4612-9995-D9CAF79F79FD@tzi.org> <36ad6759-0bce-ad05-d42c-abdd2083781c@bluepopcorn.net> <8A4D0737-333F-4801-85DA-3FA07D8C9767@tzi.org> <e5197be8-7498-f3f7-66cc-3efa3391e43e@bluepopcorn.net> <CECE482A-92A7-4A6F-A72C-DCDCDB25FFDC@tzi.org>
From: Jim Fenton <fenton@bluepopcorn.net>
Autocrypt: addr=fenton@bluepopcorn.net; prefer-encrypt=mutual; keydata= mQINBFJNz0MBEADME6UoNSsTvSDJOdzL4yWfH4HTTOOZZPUcM/at38j4joeBb2PdatlwCBtk 9ZjupxFK+Qh5NZC19Oa6CHo0vlqw7V1hx1MUhmSPbzKRcNFhJu0KcQdniI8qmsqoG50IELXN BPI5OEZ3chYHpoXXi2+VCkjXJyeoqRNwNdv6QPGg6O1FMbB+AcIZj3x5U18LnJnXv1i+1vBq CxbMP43VmryPf8BLufcEciXpMEHydHbrEBZb/r7SBkUhdQXjxRNcWOLeYvOVUOOrr1c+jvqm DEbTWUJVRnUro/WpZQBffFnymR0jjkdAa8eOVl/nF2oMLbaBsOMvxCRSSEcGhuqwbEappNVT 1nuBTbkJT/GGcXxc+lEx9uNj86oYC4384VZJMTd1BRI4qPXImNZCIdmpKegK743B6xxN6Qh1 Tg167pn9429JENQE/AFIVX5B/gpsg7Aq+3rmz9H6GbfovPvFV3TBTgsHCHAMC8XU+S4fhcqN PN0lbUeyb7g6wxaE+dYqC7TExx7G3prw4v66y0qS7ow/Cfw8XXOEkaFQ4XwP7nvfILT+9CcU yS8I40vlDFU9Wnt56CbGz0ZVQgHnwyPXL+S9kCcIwRLFx1M79s6T6qwX1TXadfpbi1uIw7XG TiPDT8Pk6i2y22oSSROyYD4D+wOhVkkvO0S8iZ3+LhAYUx86nwARAQABtCNKaW0gRmVudG9u IDxmZW50b25AYmx1ZXBvcGNvcm4ubmV0PokCVQQTAQIAPwIbAwYLCQgHAwIGFQgCCQoLBBYC AwECHgECF4AWIQS1nUkJe2fEXbvBaacbJaiwFdCfvgUCXVD9ggUJDORhvgAKCRAbJaiwFdCf vgiSEACd3Nem63zL2C6daCFfRzOANkf30Q8AvaRVwhfdFxs+5vETCzbqctrtIAHeqncXjm9G uEJWxecAiHZXKoWUEFECMp3+Saznw0np+c722M4k9xI+mxqbcE0qgpYQgA8zbS/Lbds3f/bk /00jrQg4VMkumONlh+RZVwxAsnWp8efrJsNTn0QOPZavAkPEN59wfyWQ3O4pNY8i3zum8Wge 8NS4BBMyG0fmjWgUq0K2QrTD4AKBslM2IWCLECypP1AOfHKmmTACKFOnzJJ4KspUw3hdBnS1 fvudUC8u26Q3T6rHosRqxGmgW7sQWwAusgMSa/A6zxR6soEBSsMT5Tf+VHebuz1FWE4ogrvJ InvewfYSCYzOQamYYGArcBtAzU00pUzW2Or7SlwZPHHy2EfMd0zvT7mwSYLwwwcCsWc1O/CI xHGea7PBgO3TdR0Ex254yc+NTyxF3isBC/fodF9aNWF6x6SV3VKYJ3U2uqS9ga85dZz8Qeps MwlSEGRVhVVWGbSxy0GxV5Up0yX4vl0kI0c7Tt57JCOoRBpn/lTK/7IEtZK6/uiw98KCy+BM uF7HPsgXjd/AQjSsZIJgDyVY/y7niduqhW2izNEdhV77htVbKHRf2SfJQNudWOIcOhUTlddH kOSjet+MDso61JxrFV4j/8wFno7NwpPIhD//HvKAiLkCDQRSTc9DARAAwZaXYs3OzGlpqvSH 3HR9GjSzIeP0EmsBCjpfIdZbQBwQ3ZREiMGInNxV+xkdjLDg0ctrWzUCUe3plWe5NJkpjqm+ KMc7GKhyeWJ5MZRtVrh0VpFTqi8UwYPWumAYqE1y/U1me/zHpfG9EDwdSYqMkPF76Fy5W+vh ZP2ILKaY8qWSLyH8TPl5mFGBypfT8Q6UuzlRs2aTbsTtBX/qwH7gztMRJSjQtYo20AqCgBBH IA/0xV5qDH7CVYyKyPQ4tJLQ8/xyTysUS5fewrj8lZo/G9SaNtC3CEvrJYwyA0nvYB6+hJPM qMP/tyRXM/9XY3qO4Vxuc+m5fYbTZa5GYAZNNuB5dvqI1U0sFTWBEbpAeabqCQ40ZnFSj+t1 tBuwfj4ey/oJ78WRyg5+VTvPKRRubOmZcnzj5yfTS3VGxAZb4Nsj1S2f3KLP0Z+Cv4dt893I 2JWTChw7jA1omF0QTQaBq140n084PFndBHudrZ3cz+APC89iie2HQ4jGQldXZXnGySHnHlA+ WUyZ9wgOplW9F4Q/Lps1bnuh5VttPVpNfjX8hiV48al+b+ut4nfzXAripIRWF3TL72/6JqgE KNhRKyRn0S6BidieSyHWzqJR3Roi/YNTvyXyLh6i6jtByb3FbnhYf/9olobDpj0E+kTemLrw owre85gwupSphqlzVSUAEQEAAYkCPAQYAQIAJgIbDBYhBLWdSQl7Z8Rdu8FppxslqLAV0J++ BQJdUP9SBQkM5GOPAAoJEBslqLAV0J++vZoP/1shJ+5iImGzvGUTTDJcAX6Wha+22QP0G51Z QGZbeB0gE+gDmRwd2yw0cO3y1sPoTJliUSuZ3DFIjv8CLBgDlrkUnijBWbi5YznsAZkH0vKG ESGzinJC6y/Nzf2TZokKiOaYrTYcZx8x2wxjNO+zsihm/rvhV/YnHEYd9dlV/MjAL3xtHU/9 fNcTDtF3RchADyVCxlqrRUkFj61dHxU+U5JRftyIliLltsy2Nlr4uAsxNX+tpAH2D2HLmjwx bV2fpTnFCVImtuo6ZqNZ8SMk1Xq0fBBdo3acBw42kL/qGIKS9x3NWEy8vsmQXn0QqNBd1Q62 9ghm82mHMTRKnOXqkMgICpZ0HffPf3p7zMkEqWptgEHxE6ZHm9hJMGEf8RED9DCYh+N1uFaM 7ndQPPFKlj80sGmNF9+01mO53hrxeL/WAdGox/STpTb2BDpiyrLdT/2R0vJNEfMxBBYlw1gc g8mPEwHwZ940/qql7e41TkDGUZa2a1WegKLj8hK1pgDDBptcdIvlvuk284jOZ2/jDyaBDsMf 310OoJchJ3977odtSCArybQIwMjTx0rv6dqjsuqP89jqlrGV6izqf1n4p4FNrBSWOSRGaoWD JJVHL4YUhP44G5xDBCtp3TqatLa5F2Rgxj50EFIzOuu9Pg1tBCPP1G+0EiikVTdDkC63X4RG
Message-ID: <1aa743fd-cba7-d11e-7259-37dd6e7efdca@bluepopcorn.net>
Date: Sat, 29 Feb 2020 12:04:39 -0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:68.0) Gecko/20100101 Thunderbird/68.5.0
MIME-Version: 1.0
In-Reply-To: <CECE482A-92A7-4A6F-A72C-DCDCDB25FFDC@tzi.org>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/tools-discuss/RKJWfCOcv1rfE_qMrjWsq5Z8PPE>
Subject: Re: [Tools-discuss] SPF rejection of mail to chairs
X-BeenThere: tools-discuss@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Tools Discussion <tools-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tools-discuss>, <mailto:tools-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tools-discuss/>
List-Post: <mailto:tools-discuss@ietf.org>
List-Help: <mailto:tools-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tools-discuss>, <mailto:tools-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 29 Feb 2020 20:04:48 -0000

On 2/27/20 9:55 PM, Carsten Bormann wrote:
> On 2020-02-28, at 00:08, Jim Fenton <fenton@bluepopcorn.net> wrote:
>> You're saying that this rejection is actually due to SPF and not DMARC
>> then? If that were the case, it would be a lot easier to remediate (just
>> rewrite the envelope-from address to a different domain). DMARC binds to
>> the From header field, which requires the much uglier rewriting we're
>> all seeing.
> I’m not an expert in nomenclature for ways of making email not work, so I have instead included an example of the rejection that AMSL sees when I send mail to IETF aliases.
> (I probably should collect them more rigorously, as there may be different situations in other cases.)


I stand corrected; the header you sent indeed does represent an SPF
rejection and not DMARC.

This is happening to you because of your SPF record:

tzi.org.        86400    IN    TXT    "v=spf1 mx
a:submithost.informatik.uni-bremen.de
a:imaphost.informatik.uni-bremen.de a:smtp.uni-bremen.de
ip4:134.102.50.0/24 ip4:134.102.51.0/24 ip4:134.102.22.0/24 -all"

The -all at the end is requesting that message recipients reject your
mail if it doesn't come from one of the named hosts, and
augustcellars.com (actually spamtitan.com on their behalf) is doing that.

I'm wondering why I haven't been running into that problem. I just
checked and (to my surprise) my domain's SPF record has a -all as well.
Perhaps it's because I DKIM-sign my outgoing email (you don't seem to).

From a tools standpoint, we could rewrite the envelope-from address, but
that would also have the effect of redirecting bounce messages to that
address. Unless we rewrote it to an address that redirected back to the
original sender. I wonder a bit if there are ways that those rewriting
tricks can be abused, though.

-Jim