6 ms·
Don't use SPF. It breaks mailing lists. DKIM does not, assuming a correctly configured mailing list.
by emersion 5y ago
Don't use SPF. It breaks mailing lists. DKIM does not, assuming a correctly configured mailing list.
- sshine 5y agoI wanted to ask, how does it do that? But then I googled around: https://serverfault.com/questions/611575/will-mailing-lists-break-if-spf-is-too-restrictive/611631#611631 https://serverfault.com/questions/611575/will-mailing-lists-... It seems that SPF, DKIM and DMARC can all cause failure wrt. mailing lists depending on how messages are rewritten.
- emersion 5y agoSPF will always fail. OTOH, when the mailing list doesn't do dumb stuff like mutating the subject or the body, DKIM will succeed.
- remram 5y agoSPF really shouldn't fail. SPF checks use the envelope address, not the From header. See also https://en.wikipedia.org/wiki/Sender_Rewriting_Scheme https://en.wikipedia.org/wiki/Sender_Rewriting_Scheme
- jeltz 5y agoA properly configured mailing list should work just fine with both SPF and DKIM. Especially SPF should not be an issue at all.
- emersion 5y agoA mailing list will _always_ break SPF. When forwarding messages to mailing list subscribers, the mailing list server will not match the host in the "From" header field.
- kiallmacinnes 5y agoOne of SPF's shortcomings is that is doesn't act upon the `From` header at all, which is the name/address the recipient most often is shown. Instead, it acts upon the `Return-Path` header, which a well configured mailing list will set to a domain it controls.
- emersion 5y agoAlright, I took a shortcut: SPF will verify, but for the wrong domain. It'll break when used together with DMARC's alignment checks.
- kiallmacinnes 5y ago> SPF will verify, but for the wrong domain I can see that argument, but - it's kinda a philosophical question about "who the sender is". Is the the person who typed out the text? or is it the server which transcribed that text into N new emails? The ML server will verify the original authors SPF. The N recipients will verify the ML servers SPF - the chain (which matches the series of MTA's involved) is still verified end to end. > It'll break when used together with DMARC's alignment checks. Yea, DMARC is a much bigger issue for mailing lists, but that's no reason to say "A mailing list will _always_ break SPF" - a well configured* ML has no issues with SPF at all. * And, yes - the definition of "well configured" had to change when SPF was introduced, that's of course annoying, but there has been many many years for ML operators to make these changes.
- emersion 5y ago> The ML server will verify the original authors SPF. The N recipients will verify the ML servers SPF - the chain (which matches the series of MTA's involved) is still verified end to end. The recipients have no way to check that the mailing list server has checked SPF/DKIM/DMARC. Mailing lists very rarely drop messages because of a failing SPF/DKIM/DMARC check. ARC tries to fix this, but requires recipients to trust the mailing list server. Just using plain DKIM is much better, recipients can just treat ML-forwarded emails just like direct emails.
- fogihujy 5y agoRecent versions of mailman is perfectly capable of handling both SPF and DKIM and thus bypassing problems with authentication.
- exikyut 5y agoReading the sibling comments, what would your recommendation(s) be in terms of the mailing-list-friendly version of the posted article?
- throw0101a 5y agoIf you run a mailing list, you probably need to look into ARC: > Authenticated Received Chain (ARC) is an email authentication system designed to allow an intermediate mail server like a mailing list or forwarding service to sign an email's original authentication results. This allows a receiving service to validate an email when the email's SPF and DKIM records are rendered invalid by an intermediate server's processing.[1] * https://en.wikipedia.org/wiki/Authenticated_Received_Chain https://en.wikipedia.org/wiki/Authenticated_Received_Chain
- emersion 5y agoARC requires the recipient to trust the mailing list. Better to just allow recipients to check the original DKIM signature instead.