Re: [ietf-dkim] [dmarc-ietf] draft-kucherawy-dmarc-rcpts

2016-11-21 Thread Brandon Long
In examples we've seen, the mail is delivered to a host and immediately (seconds) picked up by the spammers botnet and millions of copies sent. Short of charging an exorbitant amount of money per message sent, I don't see how any service can prevent sending a single spam message with 100% accuracy

Re: [ietf-dkim] [dmarc-ietf] draft-kucherawy-dmarc-rcpts

2016-11-21 Thread Murray S. Kucherawy
What's the actual damage here? Does, say, gmail.com's reputation suffer when it signs spam that then gets replayed? On Mon, Nov 21, 2016 at 4:04 PM, Brandon Long wrote: > In examples we've seen, the mail is delivered to a host and immediately > (seconds) picked up by the spammers botnet and mil

Re: [ietf-dkim] [dmarc-ietf] a slightly less kludge alternative to draft-kucherawy-dmarc-rcpts

2016-11-21 Thread Brandon Long
Also realize that this isn't "Gmail shouldn't sign spam", it's everyone who normally has a good reputation needs to not sign spam, this is a way to steal reputation from any service allowing you to choose your own message, and can be used against any mail receiver. That said, I think this proposal

Re: [ietf-dkim] [dmarc-ietf] a slightly less kludge alternative to draft-kucherawy-dmarc-rcpts

2016-11-21 Thread John R. Levine
Also realize that this isn't "Gmail shouldn't sign spam", it's everyone who normally has a good reputation needs to not sign spam, this is a way to steal reputation from any service allowing you to choose your own message, and can be used against any mail receiver. Just wondering, roughly when w

Re: [ietf-dkim] [dmarc-ietf] a slightly less kludge alternative to draft-kucherawy-dmarc-rcpts

2016-11-21 Thread Brandon Long
On Nov 21, 2016 6:30 PM, "John R. Levine" wrote: Also realize that this isn't "Gmail shouldn't sign spam", it's everyone who > normally has a good reputation needs to not sign spam, this is a way to > steal reputation from any service allowing you to choose your own message, > and can be used aga

Re: [ietf-dkim] [dmarc-ietf] draft-kucherawy-dmarc-rcpts

2016-11-21 Thread Brandon Long
Well, besides the obvious damage of phishing/spam mails that may make it through filters because of this, yes, this can also be used to damage the reputation of senders. Gmail can probably weather the reputation issue, since we're a large high volume service, and antispam folks would have to mitig