Re: [Tools-discuss] Weird messages from IETF/Google Mailservers (WG: PALS WG Adoption poll draft-schmutzer-pals-ple)

Robert Sparks <rjsparks@nostrum.com> Thu, 01 June 2023 20:06 UTC

Return-Path: <rjsparks@nostrum.com>
X-Original-To: wgchairs@ietfa.amsl.com
Delivered-To: wgchairs@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0659EC15106F; Thu, 1 Jun 2023 13:06:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.278
X-Spam-Level:
X-Spam-Status: No, score=-1.278 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, KHOP_HELO_FCRDNS=0.399, NICE_REPLY_A=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, T_SPF_HELO_PERMERROR=0.01, T_SPF_PERMERROR=0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (1024-bit key) reason="fail (message has been altered)" header.d=nostrum.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P7cLkJgDsrIh; Thu, 1 Jun 2023 13:06:24 -0700 (PDT)
Received: from nostrum.com (raven-v6.nostrum.com [IPv6:2001:470:d:1130::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5EDD5C14CEED; Thu, 1 Jun 2023 13:06:24 -0700 (PDT)
Received: from [192.168.1.102] ([47.186.48.51]) (authenticated bits=0) by nostrum.com (8.17.1/8.17.1) with ESMTPSA id 351K65QY088918 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NO); Thu, 1 Jun 2023 15:06:07 -0500 (CDT) (envelope-from rjsparks@nostrum.com)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=nostrum.com; s=default; t=1685649973; bh=CaZ8KFpWBsbznKchmqVNXKNmyTA8BZvETxuYttIFhxE=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=QFbhVFcMDWDQ48+jTF2klmHg6EBkv9rbKNvBvVdY/aLbGTOzVzWQRrVrDxkM9hySx YR2AchjwJnURNd3urbySZw1nzZyu5sSweVNRV6ie6RDaipQ5RJptyjE33mjniItNsT WEDjMpJydPLfhGob+6BDq7sahE5qQrDkzcC5HIHw=
X-Authentication-Warning: raven.nostrum.com: Host [47.186.48.51] claimed to be [192.168.1.102]
Message-ID: <a5761045-7c2e-530b-c41d-10656ee2ae4b@nostrum.com>
Date: Thu, 01 Jun 2023 15:06:00 -0500
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Thunderbird/102.11.2
Subject: Re: [Tools-discuss] Weird messages from IETF/Google Mailservers (WG: PALS WG Adoption poll draft-schmutzer-pals-ple)
Content-Language: en-US
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, Barry Leiba <barryleiba@computer.org>, Jim Fenton <fenton@bluepopcorn.net>
Cc: wgchairs@ietf.org, tools-discuss@ietf.org
References: <BEZP281MB2008B40D838DDC78B76B4DFA9849A@BEZP281MB2008.DEUP281.PROD.OUTLOOK.COM> <ZHinT9Y4Ffn0tcwD@faui48e.informatik.uni-erlangen.de> <9898F7C3-7139-474B-B9A6-22A6B09E7D52@bluepopcorn.net> <CALaySJLGK92TtzrpKwV3v-XcWNxLUY3wqObv=Qvkaujc=aXHcQ@mail.gmail.com> <4e5c9dbd-79a0-b89a-d827-1f4ed39f7834@gmail.com>
From: Robert Sparks <rjsparks@nostrum.com>
In-Reply-To: <4e5c9dbd-79a0-b89a-d827-1f4ed39f7834@gmail.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/wgchairs/0YZ0PNKQ8LTsSSz87APCAhEsdu0>
X-BeenThere: wgchairs@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Working Group Chairs <wgchairs.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/wgchairs>, <mailto:wgchairs-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/wgchairs/>
List-Post: <mailto:wgchairs@ietf.org>
List-Help: <mailto:wgchairs-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/wgchairs>, <mailto:wgchairs-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Jun 2023 20:06:29 -0000

I've been looking the dmarc failures for so long, I didn't see this - 
thanks for calling it out.

RjS

On 6/1/23 3:00 PM, Brian E Carpenter wrote:
> I don't think these are DMARC failures, if you look back at the
> original error messages that Toerless forwarded.
>
> There's another variant that I've seen:
>
>> This is the mail system at host ietfa.amsl.com.
>>
>> I'm sorry to have to inform you that your message could not
>> be delivered to one or more recipients. It's attached below.
>>
>> For further assistance, please send mail to postmaster.
>>
>> If you do so, please include this problem report. You can
>> delete your own text from the attached returned message.
>>
>>                    The mail system
>>
>> <bob.hinden@gmail.com> (expanded from
>>     <expand-draft-ietf-6man-rfc6874bis@virtual.ietf.org>): host
>>     gmail-smtp-in.l.google.com[2607:f8b0:4023:c06::1a] said: 421-4.7.28
>>     [2001:559:c4c7::100      15] Our system has detected an unusual rate
>>     421-4.7.28 of unsolicited mail originating from your IP address. 
>> To protect
>>     our 421-4.7.28 users from spam, mail sent from your IP address 
>> has been
>>     temporarily 421-4.7.28 rate limited. Please visit 421-4.7.28
>>     https://support.google.com/mail/?p=UnsolicitedRateLimitError to 
>> 421 4.7.28
>>     review our Bulk Email Senders Guidelines.
>>     n8-20020a056e02148800b0030f25d70b82si1211024ilk.99 - gsmtp (in 
>> reply to end
>>     of DATA command)
>>
>> <brian.e.carpenter@gmail.com> (expanded from
>>     <expand-draft-ietf-6man-rfc6874bis@virtual.ietf.org>): host
>>     gmail-smtp-in.l.google.com[2607:f8b0:4023:c06::1a] said: 421-4.7.28
>>     [2001:559:c4c7::100      15] Our system has detected an unusual rate
>>     421-4.7.28 of unsolicited mail originating from your IP address. 
>> To protect
>>     our 421-4.7.28 users from spam, mail sent from your IP address 
>> has been
>>     temporarily 421-4.7.28 rate limited. Please visit 421-4.7.28
>>     https://support.google.com/mail/?p=UnsolicitedRateLimitError to 
>> 421 4.7.28
>>     review our Bulk Email Senders Guidelines.
>>     n8-20020a056e02148800b0030f25d70b82si1211024ilk.99 - gsmtp (in 
>> reply to end
>>     of DATA command)
>
>
> Regards
>    Brian Carpenter
>
> On 02-Jun-23 02:46, Barry Leiba wrote:
>> But we *are* finishing work to standardize DMARC:
>> https://datatracker.ietf.org/doc/draft-ietf-dmarc-dmarcbis/
>> ...and there is a huge controversy in the working group about what
>> normative things to say about this, and whether we should say anything
>> normative at all.
>>
>> But this is something different; gmail appears to be seriously
>> overstepping.  I checked the DMARC record for telekom.de (TXT record
>> in _dmarc.telekom.de), and here it is:
>> v=DMARC1;p=none;rua=mailto:dmarc@telekom.de;ruf=mailto:dmarc@telekom.de;
>>
>> They are publishing a "p=none" policy, which should *not* trigger a
>> rejection because of failure to authenticate.  Yet gmail is rejecting
>> it anyway (as if the policy were p=reject).  I will ask my gmail
>> contact about this.
>>
>> Barry (chair of the DMARC working group)
>>
>> On Thu, Jun 1, 2023 at 10:38 AM Jim Fenton <fenton@bluepopcorn.net> 
>> wrote:
>>>
>>> On 1 Jun 2023, at 7:12, Toerless Eckert wrote:
>>>
>>>> Please complain with the ART email folks. It is the IETF that 
>>>> standardized all those
>>>> email "security" mechanisms such DMARC that google is now using to 
>>>> effectively make
>>>> email unusable for many people (and this is primarily what i heard 
>>>> from outside the IETF).
>>>
>>> IETF did not standardize DMARC: RFC 7489 is an informational 
>>> specification published via the independent submission track.
>>>
>>> Unfortunately many people and organizations, including some that are 
>>> mandating the deployment of DMARC and publication of “reject” 
>>> policies, so not understand the difference between informational and 
>>> standards-track.
>>>
>>> -Jim
>>>
>>
>> ___________________________________________________________
>> Tools-discuss mailing list - Tools-discuss@ietf.org - 
>> https://www.ietf.org/mailman/listinfo/tools-discuss
> ___________________________________________________________
> Tools-discuss mailing list - Tools-discuss@ietf.org - 
> https://www.ietf.org/mailman/listinfo/tools-discuss