4 ms·
I've been managing my own mail server since forwever (when nanae was still a thing: news.admin.net-abuse.email). SPF is not too bad as far as forging counterme
by livebsd 8y ago
I've been managing my own mail server since forwever (when nanae was still a thing: news.admin.net-abuse.email).
SPF is not too bad as far as forging countermeasures work. It's relatively simple both to implement and to check. I'm not against it.
What I don't like is every single other standard they pushed later. I personally think DMARC is borderline useless. DKIM is plainly horrid and breaks just about everything you'd expect from email such as mailing lists, while not solving anything both from a legitimacy perspective and from a spam perspective.
Like everybody says, the "recommended" solution is to pour each and every of these half-assed solutions into a score system. Which sucks, because when a legitimate email is rejected, the fix is never trivial: it could be just a perfectly legitimate host which decided that all these solutions are crap (and they're right).
You know my current 90+% spam and scamming source by volume? It's gmail.com. It's passing all these checks, of course. It's the reason I consider DKIM virtually useless even from a legitimacy perspective: a valid DKIM signature from any large/free email provider bears no significance to the point that even if I had a decent UI for validation in my email client, I would basically have to avoid it: "oh, right, another legit scam from gmail.com".
- lolc 8y agoMaybe consider that gmail.com is such a big source of spam exactly because the other routes are being warded off.
- marcosdumay 8y agoWhy is that relevant? All the barriers are just increasing the power of gmail, making it impossible to filter it off. It's mostly likely that the volume of spam will remain constant, whatever we do. But the current fight (led by Google, for some reason) is just breaking the email federation. By the way, now that we have all the natural language tools, what was made of content based filtering?
- lolc 8y agoIt's relevant because spammers wouldn't go to the trouble of dealing with Gmail if they had easier venues. And I disagree that the volume of spam is constant. Also content-based filtering is already huge. The threat to the federation model is clear though.
- garaetjjte 8y agoIt is SPF that completely breaks mailing lists, DKIM is necessary to fix it. DMARC just specifies reporting and policy, DKIM is almost useless (except as SPF fail override) without it (because you don't know if it should have signature or not)
- brightball 8y agoDKIM without DMARC is the issue. Mail servers have no way of knowing that an email with no DKIM signature was supposed to have one unless you’ve set a DMARC policy to make it clear.
- brightball 8y agoI worked at a company that was overloaded with phishing right when DMARC was announced and started implementing it immediately. If not for DMARC, without exaggerating at all I don’t believe that company would still be in business today. It was the only thing that really stopped the phishing directly against our domain. We built a lot of tooling for other attacks we were seeing, but that piece was critical. The trick with DMARC is that receiving email servers have no way of knowing how strictly you’ve implemented SPF and DKIM, so they guess and make their own rules unless you setup DMARC to tell them you’ve been thorough.