4 ms·
> As the mailing list software should use its own domain for the bounce addresses, the mailing list operator can set up SPF to authorize the mailing list server
by temprature 10y ago
> As the mailing list software should use its own domain for the bounce addresses, the mailing list operator can set up SPF to authorize the mailing list server as an outbound server for that domain just fine
This will make SPF pass but it has no effect on the DMARC result. For DMARC to use the SPF result, the envelope FROM needs to be aligned with the header From. Pretty much every mailing list already does what you've described but it doesn't help with DMARC.
> As for DKIM, you simply should not modify the message
Many mailing lists modify every message to add a footer with unsubscribe information. Others only modify some messages when necessary such as to convert HTML messages to plain-text, to strip attachments, to wrap lines to 72 characters etc.
- CodeWriter23 10y agoYes, modify the message and submit to the SMTP server, which calculates the DKIM signature.
- temprature 10y agoI don't understand what you mean. If you're saying the mailing list SMTP server could sign the message with their own DKIM key, that doesn't work because the DKIM result only gets used if the signing domain is aligned with the domain in the From header.
- CodeWriter23 10y agoOoops, I probably should have quoted you > Many mailing lists modify every message to add a footer with unsubscribe information. That will not affect DKIM. The DKIM signing occurs after the listserv creates the email message and hands it off to the SMTP server.
- temprature 10y ago> That will not affect DKIM. It will affect DKIM and it does. > The DKIM signing occurs after the listserv creates the email message and hands it off to the SMTP server. The DKIM signing occurs before the listserv even receives the message. It's done by the sender's SMTP server before it gets relayed. The listserv receives the signed message and adds a footer which breaks the signature.
- CodeWriter23 10y agoThe listserv has to copy any incoming email message and send one copy of the inbound message to each recipient on the listserv list. To assure deliverability, it has to send it from it's own address @ it's own domain, to avoid SPF failure. Each individual copy is passed by the listserv to the SMTP server to go to each recipient on the listserv list. The SMTP server calculates the DKIM on each message as it is sent. Again, mail servers adding links is completely irrelevant to the DKIM signing process.
- temprature 10y ago> it has to send it from it's own address @ it's own domain, to avoid SPF failure. To avoid SPF failure it uses its own domain in the MAIL FROM envelope address. There are very few lists that change the From header, I can't name a single one although they probably do exist. > The SMTP server calculates the DKIM on each message as it is sent. Like I said, even if they did, that only works if they were also changing the From header to their own domain. Otherwise, even though there is a valid DKIM signature there is no alignment with the From header so it is ignored when evaluating DMARC. DKIM does not use the MAIL FROM address. > Again, mail servers adding links is completely irrelevant to the DKIM signing process. I send a mail to a mailing list, LKML is a good example. My SMTP server signs the message with my DKIM private key and relays it to the LKML SMTP server. LKML receives it, appends a footer and relays it to all subscribers, with my name and email address in the From header but using its own address in the MAIL FROM address. The footer breaks the DKIM signature because when my message was signed that footer wasn't there. LKML does not re-sign the outgoing messages, it relays the DKIM signature provided in the original message. This is standard of many, possibly even most, mailing lists.