Re: [dmarc-ietf] Is From spoofing an interoperability issue or not?

2023-04-19 Thread Jesse Thompson
On Wed, Apr 19, 2023, at 12:35 PM, Alessandro Vesely wrote: > On Wed 19/Apr/2023 15:37:25 +0200 Laura Atkins wrote: > > To me it’s not so much the company can’t delegate authentication - it’s how > > many SaaS providers (some of which are ESPs and some of which are 3rd > > parties > > that send

Re: [dmarc-ietf] Is From spoofing an interoperability issue or not?

2023-04-19 Thread Alessandro Vesely
On Wed 19/Apr/2023 15:37:25 +0200 Laura Atkins wrote: To me it’s not so much the company can’t delegate authentication - it’s how many SaaS providers (some of which are ESPs and some of which are 3rd parties that send through ESPs) are incapable of supporting DMARC alignment. Not it’s hard, not

Re: [dmarc-ietf] Signaling MLMs

2023-04-19 Thread Alessandro Vesely
On Wed 19/Apr/2023 15:50:54 +0200 Benny Pedersen wrote: Alessandro Vesely skrev den 2023-04-19 11:09: if all maillist did arc on incoming mails before mailman scraped dkim then all will be good, only left is dmarc is not in all places tests arc results It is all too easy to spoof an ARC chain

Re: [dmarc-ietf] Is From spoofing an interoperability issue or not?

2023-04-19 Thread John Levine
It appears that Laura Atkins said: >That was my question: is it an interop issue that ESPs (whether they be your >traditional ESP or a SaaS provider that sends >mail on behalf of their customers) cannot support custom domains in the SPF >and DKIM and thus cannot support DMARC? Many of >the curr

Re: [dmarc-ietf] Is From spoofing an interoperability issue or not?

2023-04-19 Thread Scott Kitterman
On April 19, 2023 1:37:25 PM UTC, Laura Atkins wrote: > > >> On 19 Apr 2023, at 14:20, John Levine wrote: >> >> It appears that Jesse Thompson said: >>> -=-=-=-=-=- >>> >>> On Mon, Apr 17, 2023, at 8:37 AM, Laura Atkins wrote: Should the IETF make the interoperability recommendation th

Re: [dmarc-ietf] Signaling MLMs

2023-04-19 Thread Benny Pedersen
Alessandro Vesely skrev den 2023-04-19 11:09: Benny is telling the world “ietf.org [1] is authorize to resign on my behalf” via DNS.  No headers required.  No delayed learning necessary. How would I get a clue of that? reading books ? if all maillist did arc on incomming mails before mailma

Re: [dmarc-ietf] Is From spoofing an interoperability issue or not?

2023-04-19 Thread Laura Atkins
> On 19 Apr 2023, at 14:20, John Levine wrote: > > It appears that Jesse Thompson said: >> -=-=-=-=-=- >> >> On Mon, Apr 17, 2023, at 8:37 AM, Laura Atkins wrote: >>> Should the IETF make the interoperability recommendation that SaaS >>> providers who send mail on behalf of companies suppor

Re: [dmarc-ietf] Is From spoofing an interoperability issue or not?

2023-04-19 Thread John Levine
It appears that Jesse Thompson said: >-=-=-=-=-=- > >On Mon, Apr 17, 2023, at 8:37 AM, Laura Atkins wrote: >> Should the IETF make the interoperability recommendation that SaaS providers >> who send mail on behalf of companies support >aligned authentication? That means custom SPF domains and cu

Re: [dmarc-ietf] DSAP "DKIM Sender Authorization Protocol" for DMARC

2023-04-19 Thread Douglas Foster
Hector, does your proposal allow for constrained delegation? I think we have a problem if this type of third-party signing allows any account at the list domain to impersonate any account in any participating domain. DF On Sat, Apr 8, 2023, 2:01 PM Hector Santos wrote: > Summary: > > I would

Re: [dmarc-ietf] Signaling MLMs

2023-04-19 Thread Alessandro Vesely
On Wed 19/Apr/2023 01:13:48 +0200 Benny Pedersen wrote: Hector Santos skrev den 2023-04-18 20:47: So your verifier see Benny’s as suspicious because of arc=fail? it does imho not fail on my own arc ? My filter attempts to recover DKIM signatures after MLM transformation, but not ARC chain