[dmarc-discuss] amazon.de fail

2015-06-15 Thread A. Schulze via dmarc-discuss
Hello, someone from amazon Germany may be interested. Again: I guess it's a legit message from amazon, otherwise let me know ... Authentication-Results: idvmailin13.datevnet.de; dkim=pass (1024-bit key; unprotected) header.d=amazonses.com header.i=@amazonses.com header.b=IGahw/4Y Authentica

Re: [dmarc-discuss] amazon.de fail

2015-06-16 Thread John Levine via dmarc-discuss
In article <20150616080608.horde.np0fbkrfk-jumt5krom4...@andreasschulze.de> you write: >someone from amazon Germany may be interested. >Again: I guess it's a legit message from amazon, otherwise let me know ... It looks fine. How does your code pass the DKIM validation results to the DMARC code

Re: [dmarc-discuss] amazon.de fail

2015-06-16 Thread A. Schulze via dmarc-discuss
Hello John, John Levine via dmarc-discuss: It looks fine. in which sense? - RFC5322.From is "amazon.DE" - SPF pass for "bounces.amazon.COM" - DKIM pass for "amazonses.COM" so neither SPF nor DKIM is aligned. according to the published record the message should be quarantined: $ opendmarc-

Re: [dmarc-discuss] amazon.de fail

2015-06-16 Thread Elizabeth Zwicky via dmarc-discuss
In one version you also havedkim=pass (1024-bit key; unprotected) header.d=amazon.de  header.i=@marketplace.amazon.de header.b=AOE4Rr31 which is an aligned pass because marketplace.amazon.de inherits amazon.de's record which doesn't specify strictness of alignment and therefore defaults to rela

Re: [dmarc-discuss] amazon.de fail

2015-06-16 Thread John Levine via dmarc-discuss
>Would be good to hear from Murray if this is the intended use-case for >OpenDMARC. In general I know OpenDMARC simply as an A-R header parser. >So my assumptions could not be completely wrong... I call the libraries directly, so in my implementation nothing parses A-R headers at all. R's, John

Re: [dmarc-discuss] amazon.de fail

2015-06-16 Thread A. Schulze via dmarc-discuss
Am 16.06.2015 um 20:22 schrieb Elizabeth Zwicky via dmarc-discuss: In one version you also have dkim=pass (1024-bit key; unprotected) header.d=amazon.de header.i=@marketplace.amazon.de header.b=AOE4Rr31 which is an aligned pass because marketplace.amazon.de inherits amazon.de's record which do

Re: [dmarc-discuss] amazon.de fail

2015-06-17 Thread A. Schulze via dmarc-discuss
A. Schulze via dmarc-discuss: someone from amazon Germany may be interested. Again: I guess it's a legit message from amazon, otherwise let me know ... further investigations made the picture more clear: Most messages in question usually have two dkim signatures (amazonses.com+amazon.de) wh

Re: [dmarc-discuss] amazon.de fail

2015-06-18 Thread Murray Kucherawy via dmarc-discuss
On 6/16/15, 10:02 AM, "A. Schulze via dmarc-discuss" wrote: >Oh, never thought about that. I know that scheme (separate A-R header) >since years. You're right. they may be combined to only one A-R. >But the way I use it they insert multiple A-R header. > >Would be good to hear from Murray if this

Re: [dmarc-discuss] amazon.de fail

2015-06-18 Thread Murray Kucherawy via dmarc-discuss
On 6/16/15, 11:39 AM, "A. Schulze via dmarc-discuss" wrote: >It's a little bit confusing. I have two unrelated issues. >The one mentioned above looks like a bug in OpenDMARC. >But that's unconfirmed by Murray... If you have evidence of a bug, please put it in a ticket on SourceForge. I don¹t che