4 ms·
The promise behind SPF, DKIM and DMARC is that they allowed positive reputation mechanisms, which cannot work if any domain is easy to spoof. So if you're caref
by giomasce 4y ago
The promise behind SPF, DKIM and DMARC is that they allowed positive reputation mechanisms, which cannot work if any domain is easy to spoof. So if you're careful, only send good email and stop sending when the recipient asks, that should be a golden star on your review, destination domains will happily let your email through and nobody will be able to freeride on your good reputation because your domain is authenticated.
However, this is still hard to establish, because it depends on the destination domain server to decide whether you're sending good stuff or not. I would like to have a mechanism by which the user can decide.
I imagine something like this: each email provider, say Gmail, issues to its users a number of single use codes like "Sor7xeik". When the user wants to subscribe to a newsletter (say news@interesting.com) it gives its own email address and one of those codes. The first email from news@interesting.com contains some header like
Authorized-Sender: authorize Sor7xeik
When Gmail receives it, scratches the code and marks @interesting.com as an authorized domain. From that point on, all (DMARC validated) emails from @interesting.com having some header like
Authorized-Sender: yes
are deemed to be interesting for that specific user, and accepted without further spam filtering. The user can revoke the consent at any time on Gmail's web interface, at which point emails from @interesting.com (with that header) will be rejected. The sender at @interesting.com will see the rejection and disable mail sending for that user.
With this mechanism bad practices like address harvesting and selling become much less useful (because an address alone is not that useful, if the sender is not authorized; and the authorization must be initiated by the user).
BTW, I am not saying that all emails should be sent with this authorized sender mechanism. I don't expect individual users to collect authorizations for each of their contacts. Email without the Authorized-Sender header would still be subject to the usual spam filtering, but agencies that often send legitimate mass emails can have a mechanism to prove that they're doing it with the user authorization.