[Mailman-Users] Add PayPal to DNs publishing DMARC p=reject

2014-05-04 Thread Stephen J. Turnbull
Lindsay Haisley writes:

 > $ dig +short -t txt _dmarc.paypal.com
 > "v=DMARC1\; p=reject\; rua=mailto:d...@rua.agari.com\; 
 > ruf=mailto:d...@bounce.paypal.com,mailto:d...@ruf.agari.com";
 > 
 > This probably is a problem of lesser magnitude than Yahoo! and AOL

FWIW, I don't consider it a "problem" at all (most definitely YMMV, of
course).  I think this is what DMARC *should* be used for.

My interpretation is that this is a particular author (a corporate
one) allowing her MTA to digitally sign "her" mail, and soliciting the
help of "email for those who can't implement Diffie-Hellman off the
top of their heads" email providers' MTAs in the effort to protect the
author's customers from 3rd party fraud.

I don't know what "paypal-inc.com" is for, so I can't speak to that
one.

Steve
--
Mailman-Users mailing list Mailman-Users@python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
https://mail.python.org/mailman/options/mailman-users/archive%40jab.org


Re: [Mailman-Users] Add PayPal to DNs publishing DMARC p=reject

2014-05-04 Thread Peter Shute
Larry Finch wrote:
 
> This is probably the first actual practical application of 
> DMARC p=reject that I have seen. Unfortunately, Yahoo's and 
> AOL's abuse of DMARC will tend to neutralize the benefit of 
> DMARC to financial institutions who have a really serious 
> spoofing problem.

How does Yahoo's DMARC policy reduce the benefit of Paypal's? Because servers 
can't follow the reject recommendation without 

And does the emergence of legitimate p=reject policies mean it's now less 
likely Yahoo and AOL will back down?

Here's a cpanel forum thread about the problem, discussing when cpanel's 
version of mailman will incorporate the features necessary to deal with the 
problem:
http://forums.cpanel.net/f43/yahoos-new-dmarc-policy-causing-mailman-bounces-402751.html

Peter Shute
--
Mailman-Users mailing list Mailman-Users@python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
https://mail.python.org/mailman/options/mailman-users/archive%40jab.org


Re: [Mailman-Users] Add PayPal to DNs publishing DMARC p=reject

2014-05-04 Thread Lindsay Haisley
On Sun, 2014-05-04 at 20:58 +, John Levine wrote:
> >$ dig +short -t txt _dmarc.paypal.com
> >"v=DMARC1\; p=reject\; rua=mailto:d...@rua.agari.com\; 
> >ruf=mailto:d...@bounce.paypal.com,mailto:d...@ruf.agari.com";
> 
> I'm on lots of lists with Paypal employees, who consistently use
> paypal-inc.com addresses, specicially to avoid DMARC problems.

$ dig +short -t txt _dmarc.paypal-inc.com
"v=DMARC1\; p=reject\; rua=mailto:d...@rua.agari.com\; 
ruf=mailto:d...@bounce.paypal.com,mailto:d...@ruf.agari.com";

No joy :(

-- 
Lindsay Haisley   | "Everything works if you let it"
FMP Computer Services |
512-259-1190  |  --- The Roadie
http://www.fmp.com|

--
Mailman-Users mailing list Mailman-Users@python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
https://mail.python.org/mailman/options/mailman-users/archive%40jab.org


Re: [Mailman-Users] Add PayPal to DNs publishing DMARC p=reject

2014-05-04 Thread Lindsay Haisley
On Sun, 2014-05-04 at 16:14 -0400, Larry Finch wrote:
> 
> On May 4, 2014, at 4:07 PM, Lindsay Haisley  wrote:
> 
> > $ dig +short -t txt _dmarc.paypal.com
> > "v=DMARC1\; p=reject\; rua=mailto:d...@rua.agari.com\; 
> > ruf=mailto:d...@bounce.paypal.com,mailto:d...@ruf.agari.com";
> > 
> > This probably is a problem of lesser magnitude than Yahoo! and AOL since
> > few list posts will come from PayPal, or be delivered to such an address
> > from a list.  It might, however, occur by accident, or by a future
> > change whereby PayPal account holders to use their DN, and although I
> > can't imagine PayPal doing this, nothing seems to be sacrosanct or
> > certain in the Wild, Wild West that is the Internet.  
> > 
> > It's more likely that a list might add a PayPal general customer
> > notifications address of some sort to a list, with nomail set, for the
> > benefit of other list subscribers.
> 
> This is probably the first actual practical application of DMARC
> p=reject that I have seen. Unfortunately, Yahoo’s and AOL’s abuse of
> DMARC will tend to neutralize the benefit of DMARC to financial
> institutions who have a really serious spoofing problem.

Add also:

chasebank.com
bankone.com
jpmorgan.com

... just random hits checking on financial institutions.

-- 
Lindsay Haisley   | "Everything works if you let it"
FMP Computer Services |
512-259-1190  |  --- The Roadie
http://www.fmp.com|

--
Mailman-Users mailing list Mailman-Users@python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
https://mail.python.org/mailman/options/mailman-users/archive%40jab.org

Re: [Mailman-Users] Add PayPal to DNs publishing DMARC p=reject

2014-05-04 Thread Larry Finch


On May 4, 2014, at 4:07 PM, Lindsay Haisley  wrote:

> $ dig +short -t txt _dmarc.paypal.com
> "v=DMARC1\; p=reject\; rua=mailto:d...@rua.agari.com\; 
> ruf=mailto:d...@bounce.paypal.com,mailto:d...@ruf.agari.com";
> 
> This probably is a problem of lesser magnitude than Yahoo! and AOL since
> few list posts will come from PayPal, or be delivered to such an address
> from a list.  It might, however, occur by accident, or by a future
> change whereby PayPal account holders to use their DN, and although I
> can't imagine PayPal doing this, nothing seems to be sacrosanct or
> certain in the Wild, Wild West that is the Internet.  
> 
> It's more likely that a list might add a PayPal general customer
> notifications address of some sort to a list, with nomail set, for the
> benefit of other list subscribers.

This is probably the first actual practical application of DMARC p=reject that 
I have seen. Unfortunately, Yahoo’s and AOL’s abuse of DMARC will tend to 
neutralize the benefit of DMARC to financial institutions who have a really 
serious spoofing problem.

best regards,
Larry

--
Larry Finch
finc...@portadmiral.org



--
Mailman-Users mailing list Mailman-Users@python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
https://mail.python.org/mailman/options/mailman-users/archive%40jab.org


[Mailman-Users] Add PayPal to DNs publishing DMARC p=reject

2014-05-04 Thread Lindsay Haisley
$ dig +short -t txt _dmarc.paypal.com
"v=DMARC1\; p=reject\; rua=mailto:d...@rua.agari.com\; 
ruf=mailto:d...@bounce.paypal.com,mailto:d...@ruf.agari.com";

This probably is a problem of lesser magnitude than Yahoo! and AOL since
few list posts will come from PayPal, or be delivered to such an address
from a list.  It might, however, occur by accident, or by a future
change whereby PayPal account holders to use their DN, and although I
can't imagine PayPal doing this, nothing seems to be sacrosanct or
certain in the Wild, Wild West that is the Internet.  

It's more likely that a list might add a PayPal general customer
notifications address of some sort to a list, with nomail set, for the
benefit of other list subscribers.

-- 
Lindsay Haisley   | "Everything works if you let it"
FMP Computer Services |
512-259-1190  |  --- The Roadie
http://www.fmp.com|

--
Mailman-Users mailing list Mailman-Users@python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
https://mail.python.org/mailman/options/mailman-users/archive%40jab.org


Re: [Mailman-Users] accessing relay mailman server from its own network

2014-05-04 Thread Anne Wainwright
if this is a duplicate, my error, don't see my post anywhere.
see below

On Thu, May 01, 2014 at 05:19:35PM -0700, Mark Sapiro wrote:
> On 05/01/2014 11:31 AM, Anne Wainwright wrote:
> > 
> > I still have dyndns addresses showing on the numeric/alpha address
> > listing both locally and from outside
> 
> 
> I do not understand "the numeric/alpha address listing"
The 0-9A-Z table of members under Membership Management - sorry if
unclear.

> 
> Where specifically do you see these?
> 
> 
> > I have changed DEFAULT_URL_HOST in mm_cfg.py appropriately, cleared the
> > browser caches. Where can this be dyndns be hiding, or is it time to run 
> > the fix_url script?
> 
> 
> Probably. See the FAQ at .
This did however resolve the issue

with thanks
Anne
> 
> -- 
> Mark Sapiro The highway is for gamblers,
> San Francisco Bay Area, Californiabetter use your sense - B. Dylan
> --
> Mailman-Users mailing list Mailman-Users@python.org
> https://mail.python.org/mailman/listinfo/mailman-users
> Mailman FAQ: http://wiki.list.org/x/AgA3
> Security Policy: http://wiki.list.org/x/QIA9
> Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
> Unsubscribe: 
> https://mail.python.org/mailman/options/mailman-users/anotheranne%40fables.co.za
--
Mailman-Users mailing list Mailman-Users@python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
https://mail.python.org/mailman/options/mailman-users/archive%40jab.org