7 ms·
Learn and Test DMARC
- scohesc 3y agoIt is absolutely astonishing that we rely on layers and layers of shims/compatibilities/hacks to keep a technology that was well-meaning and ideal 30ish+ years ago running in the 21st century. Same thing in the VOIP/telecom space. Microsoft recently had issues with mail deliverability - most of our O365 tenants had a notice reminding us to check SPF, DKIM, DMARC (we're configured properly already) - some of our tenants were having issues mailing smaller mail providers (ISP-level) because the small provider is outright blocking IPs and IP ranges due to spam coming from the same IP address/mail server we're trying to send from.
- graypegg 3y agoThis is so cool! I would love to see this for other protocols actually, maybe SSL or something!
- alt227 3y agoThe UK Government provide a similar check which is a lot more user friendly. I use it for sending reports to upper management, who just want to see big green ticks next to our domain names: https://emailsecuritycheck.service.ncsc.gov.uk/check https://emailsecuritycheck.service.ncsc.gov.uk/check
- deleted 3y ago[deleted]
- supriyo-biswas 3y agoFor TLS, there’s https://bytebybyte.dev/ https://bytebybyte.dev/ and https://tls13.xargs.org/ https://tls13.xargs.org/
- teddyh 3y agoSee also: <https://webencrypt.org/illustrated-tls/ https://webencrypt.org/illustrated-tls/>
- supriyo-biswas 3y ago(For reference, the original is here, https://tls13.xargs.org/ https://tls13.xargs.org/)
- patmorgan23 3y agohttps://www.ssllabs.com/ssltest/ https://www.ssllabs.com/ssltest/
- alt227 3y agoSSLLabs is awesome, I use it regularly for work. So much information returned that it is like a school day reading through the results.
- deleted 3y ago[deleted]
- Geezus_42 3y agoDmarcian
- Geezus_42 3y agodmarcian.com
- smartbit 3y agohttps://internet.nl https://internet.nl
- dang 3y agoRelated: See how DMARC, SPF, and DKIM work interactively - https://news.ycombinator.com/item?id=29869266 https://news.ycombinator.com/item?id=29869266 - Jan 2022 (108 comments)
- deleted 3y ago[deleted]
- pests 3y agoVery cool. > For DMARC to pass, DKIM and/or SPF checks need to pass and the domains must be in alignment. AFAIK this is incorrect. It is not "and/or" but rather "or" - only DKIM or SPF needs to pass. There is no method to require both.
- deleted 3y ago[deleted]
- pests 3y agoThis was a recent problem with Cloudflares partnership with MailChannels[1] that allowed email spoofing which was related to this. The basic problem being that mailchannel did not require authentication - cloudflare workers could just hit an API endpoint on mailchannel to send email. Mailchannel required you to add an include: record to your SPF policy. This allowed anyone to impersonate anyone else due to mailchannel being a valid sender for all domains. Only ~400 domains of the 2M hosted had DKIM set up but even if they did the passing SPF caused DMARC to pass. [1] https://blog.cloudflare.com/sending-email-from-workers-with-mailchannels/ https://blog.cloudflare.com/sending-email-from-workers-with-...
- bawolff 3y agoI mean i dont think requiring dkim would stop attacks based on totally broken authentication. In that scenario, mailchimp might as well be signing the emails for the incorrect domain as well.
- pests 3y agoTrue. MailChannels, not MailChip though. They handle email for a lot of webhosting providers.
- ttul 3y agoAppreciate the skepticism; it keeps us on our toes. Let's cut to the chase: Domain Lockdown: We added this to our Cloudflare Workers integration. It mandates a DNS TXT record to authorize a Worker to send emails from a specific domain. You can't forge the CF-Worker header, so impersonation is off the table. Pre-Lockdown Vulnerability: Yes, we were more exposed before. Thanks to the researchers who pointed it out, we've patched this up with Domain Lockdown. SMTP Relay & Web Hosting: Domain Lockdown isn’t mandatory yet in the rest of our service for the web hosting industry. But we’re developing updates for our cPanel WHM plugin and other integrations to make this scalable for millions of domains. Note that our service has to work for applications like public mailing lists where locking the sender domain down breaks stuff. Scale & Standardization: We service a broad range of configurations. Rolling out universal changes takes time. We're also working with industry groups like M3AAWG to push for improvements to DMARC and other standards to help everyone be more secure. Tech docs for the curious: https://support.mailchannels.com/hc/en-us/articles/456589835 https://support.mailchannels.com/hc/en-us/articles/456589835... Appreciate all the questions and criticism here. reply
- guessmyname 3y agoI sent an email via Apple’s “Hide My Email” service [1]. > Unhandled Promise Rejection: > TypeError: a.from.replace(/[<]/gi," is not a function. (In 'a.from.replace(/[<]/gi,"(")', 'a.from.replace(/[<]/gi,"' is undefined) > dist.min.js:3:32767 This error occurred after the interface began displaying the following information: > Here are the message headers and message body: > DKIM-Signature: d=icloud.com s=1a1hai It’s been over a year since the website was featured on Hacker News (January 10, 2022), so I suspect that the JavaScript code may have become outdated and non-functional. It’s possible that it never supported Safari browsers in the first place, or perhaps it’s a combination of both issues. Nevertheless, I’ve learned a lot from the initial [2] and second [3] parts of the DMARC test, which gives me some insight into what might be happening in the subsequent steps. [1] https://support.apple.com/en-us/HT210425 https://support.apple.com/en-us/HT210425 [2] dig +noall +answer -t TXT <EMAIL_DOMAIN> | grep -i SPF [3] dig +noall +answer -t A <HOSTNAME>
- jauntywundrkind 3y agoYou sent an email without a "from" field and it broke. Programmer didn't think to test for bad users doing bad things. Nothing special here, no big conspiracy.
- deleted 3y ago[deleted]
- anamexis 3y agoIt's not a "bad user doing bad things," it's a widely-used email forwarding service.
- jeroenhd 3y agoIf this is true and Apple's service does leave out a "from" header (it may just as well be a parse error somewhere on the website's side) that would definitely be on the mail forwarding service, not on this particular website. RFC 5322 and RFC 2822 specify that at least and at most one From: header must be present. Mail services that don't add at least some kind of fake From header aren't spec compliant and should probably expect error and delivery problems. RFC 2822 is over 20 years old now. In theory Apple's service could only be RFC 822 compliant, but this does pose a big interoperability problem for its customers.
- ChrisArchitect 3y agoBunch of discussion from 2022: https://news.ycombinator.com/item?id=29869266 https://news.ycombinator.com/item?id=29869266
- normaldist 3y agoAppears to be operated by uriports.com, in case anyone wondered where their email was going..
- BOOSTERHIDROGEN 3y agoIs that a bad thing or what ?
- amelius 3y agoThis is how email is supposed to work. In reality, there are whitelists ...
- systems_glitch 3y agoAnd blacklists. And predatory blacklists. And blacklists that amount to organized extortion.
- emaildelivboy 3y agoHello UCEPROTECT. The only blocklist that matters is SPAMHAUS. Other blocklists at the inbox provider level are behind the curtain.
- sgt 3y agoWhitelists for what? Having a pre-determined whitelist for domains allowed to send to your domain is not common. That would defeat the purpose of e-mail.
- ingen0s 3y agoDope af
- deleted 3y ago[deleted]
- Rookie42 3y agoGreat way of pushing the critical email services we all need to reduce spam. While I have always wanted SPF, DKIM and DMARC to be enough of an incentive for the businesses i work with, reputation is often not enough of a driver to prioritise the investment. But fret not! For when you are dealing with companies which want to communicate with customers in a trusted way, there is a marketer's dream standard - Brand Indicators for Message Identification (BIMI) - now security isnt the only outcome, you get a pretty logo too! https://www.litmus.com/blog/what-is-bimi-and-why-should-email-marketers-care https://www.litmus.com/blog/what-is-bimi-and-why-should-emai... I have used BIMI at multiple companies now which talk about Customer Experience to drive the proper (P=Reject) implementation of DMARC.
- tamiral 3y agoisnt BIMI like $1000/yr?
- Rookie42 3y agoYes, it is - well worth it for companies that perceive value for that investment, but that is all part of the value analysis.
- jeroenhd 3y agoDMARC still has some issues. From a few years ago: https://i.blackhat.com/USA-20/Thursday/us-20-Chen-You-Have-No-Idea-Who-Sent-That-Email-18-Attacks-On-Email-Sender-Authentication-wp.pdf https://i.blackhat.com/USA-20/Thursday/us-20-Chen-You-Have-N... > Unfortunately, neither SPF nor DKIM provides a complete solution for preventing email spoofing. SPF authenticates the HELO/MAIL FROM identifier and DKIM authenticates the d= field in DKIM-signature header: neither of them authenticates the From header displayed to the end-user, which means that even if an email passes SPF and DKIM validation, its From address can still be forged. A lack of DMARC+ on an email domain is definitely a problem, but DMARC+ alone still doesn't solve the "is this the real sender" problem.
- Rookie42 3y agoIt inst perfect, but it doesn't need to be unless your risk is disproportional to the market. Risk will always be there, you just need to manage it inline with your corporate risk tolerance - and implementing DMARC to P=Reject is most likely going to (very likely exceed) that approach. Yes, some companies have elevated risk here (Banks, Payment Processors, Social Media companies) - but honestly most don't. Btw - this is as much an acceptance as a survival strategy - nothing will ever be perfect, not without significant cost & impact elsewhere. Survival of the fittest these days is managing (and please the understanding of) risk better than others
- aeturnum 3y agoI really appreciate the iterative way it goes through the process. It's been a few years but this would have been a godsend at a previous company when we were trying to move to self-hosted email sending with all the proper security measures.
- throwaway892238 3y agoFun fact: sns.amazonaws.com still has no DMARC record. This is where AWS SNS messages originate from unless you use a custom domain, and it's where all CloudWatch alerts come from (no-reply@sns.amazonaws.com)
- emaildelivboy 3y agoDMARC is and has always been...fine, save for the fact that most phishing / exploits are sent using cousin domains. Is a DMARC policy necessary and a great security measure? Sure. Is it a domain identity security game changer?... no way.
- blitzar 3y agoIs a DMARC policy necessary and a great security measure to stop most phishing / exploits being sent using your cousin domains ...
- RektBoy 3y agoPeople, don't forget to properly set all these checks for DNS failover. I saw companies got scammed, because they used default settings in Exchange Online. And attacker just made the DNS "unavailable" for brief moment and all phishing emails passed. Because MS server responded with DNS "temp error" and pass all emails as not a spam. (detailed: received-spf: TempError (protection.outlook.com: error in processing during lookup of <phished domain>: DNS Timeout) and DKIM is checked on domain of sender's SMTP server, in this case attacker's server used for phishing ) Then I had the great experience with MS IT/security support, people there can't even understand how emails works, very funny and sad experience. I hope outsourcing works for them.
- blacklion 3y agoDoes anybody know open-source or, at least, free way to process DMARC reports? I have several e-mail domains with SPF, DKIM and DMARC enabled, and it works, but I have two annoying problems with DMARC: (1) Some sites like to send DMARC reports which says "you send us 3 messages, everything is OK, all checks are passed, you are clear". (2) Sometimes my domains are used to (try to) send spam via other servers and I got DMARC reports like "this <IP> tired to spam with your domain in HELO/FROM and we killed it, as checks failed". Both reports are of no use for me: I don't want to know, that my users send mail to @gmail.com and @mail.ru (first reports) and I can do nothing about second case, as these <IP>s are not <IP>s of my server, so what should I do? Some filter or dashboard will be very useful, as unpacking & checking XMLs by hands are very cumbersome.
- pch00 3y agodmarcian have a free "personal" tier: https://dmarcian.com/pricing/ https://dmarcian.com/pricing/
- JulianWasTaken 3y agoparsedmarc (https://github.com/domainaware/parsedmarc https://github.com/domainaware/parsedmarc) is the one I've had starred to look at, but no first-hand use yet.
- hannob 3y agoHere's a script I wrote for myself: https://github.com/hannob/rpter https://github.com/hannob/rpter It gives a summary of reports, and details for failures. Not super sophisticated, but should be simple enough to extend. Also parses SMTP-TLS reporting.