7 ms·
DMARC has been public since 2012 but most company domains still don't enforce it
- smartmic 2mo agoI am self-hosting my (secondary) email and have only implemented SPF and DKIM. This works fine on a practical level for me. What would be the benefit of setting up DMARC on top?
- asimpletune 2mo agoBecause if someone spoofs an email coming from your domain DMARC tells the receiver what to do with the spoofed email.
- kamma4434 2mo agoAnd what is the sane way to handle a spoofed email?
- azeemba 2mo agoThat's what the policy setting tells the recipient. You can tell them to trest it as normal, send it to spam or delete it. The report that they send you is useful for you to make sure your emails that you expect to go through are going through.
- winstonwinston 2mo agoRealistically spoofed address (unauthenticated email) will be treated as spam and it’ll be implicitly quarantined or rejected as such by many well-known mail receivers. You can make this an explicit “reject” by publishing DMARC policy for your domain. For example, gmail.com treats unauthenticated email as spam implicitly, regardless of DMARC policy.
- thesuitonym 2mo ago`p=reject`, ESPECIALLY for your personal email. `p=quarantine` is really only useful if you suspect your marketing department has set up some email blaster somewhere.
- toast0 2mo agoReject it in the SMTP transaction.
- comrade1234 2mo agoGoogle, Microsoft, Amazon and others send me summary reports of people spoofing my domains. I have dmarc set for them to accept the email, mark it spam (presumably) and send me a report. I really should and can tell them to reject the spam completely - another setting in dmarc but haven't yet out of laziness basically.
- AshamedCaptain 2mo agoAnd SPF doesn't?
- ivlad 2mo agoTechnically, no. SPF allows to say “these IPs are authorised to send emails as example.com”, where DMARC allows to say “I as domain owner recommend to quarantine emails that fail SPF and DKIM”, it also allows finer alignment (ie, matching between different “from” parameters) configuration and reporting by the receivers. Of course, with absence of DNARC policies, receivers default to some internal defaults, or may ignore the policies altogether. But at least, the big ones send DMARC reports.
- wolttam 2mo agoNot always. An email has a valid SPF when its return path email’s domain permits the sending server’s IP. But that email may have a forged From: header (which causes an SPF mis-alignment), and the receiving server checks the DMARC of *the From header* domain to determine how to handle that mis-alignment.
- aaronmdjones 2mo agoNo, it doesn't. In the following SMTP conversation: MAIL FROM: foo@example.net RCPT TO: victim@example.com DATA From: service@paypal.co.uk To: victim@example.com Subject: We are updating our Terms of Service [...] SPF checks whether the sending host is allowed to send e-mail from example.net (the envelope sender). The recipient sees service@paypal.co.uk (the From address on the inner message), because most ESPs do them the great disservice of not indicating that the sender identities are not aligned. Adding a DMARC record to a domain requires that e-mail whose inner messages claim to be from that domain must have sender alignment to the envelope sender. The above message would pass SPF (if the spammer owns example.net and has created SPF records for themselves) but would fail DMARC (paypal.co.uk's DMARC record exists, so alignment is required, and yet example.net != paypal.co.uk, so they are not aligned). In this case their DMARC policy says to reject the message, so (if the recipient is checking DMARC) it would either be rejected outright or it would land in Spam/Quarantine rather than Inbox.
- bombcar 2mo agoThe biggest benefit I saw in a small domain was greatly reduced backscatter spam. Before someone’d randomly make up a billion emails on my domain and send “from” them, and I’d get various out of office replies, etc (catch all) - that basically never happens anymore.
- inigyou 2mo agoThat affects your reputation BTW as they have no way to know they aren't really from your domain.
- cube00 2mo ago> What would be the benefit of setting up DMARC on top? Some mail providers will junk your mail if you don't have a reject/quarantine DMARC policy because you're seen as enabling the spammers so everything out of your domain must be punished.
- account42 2mo ago[citation needed]
- cube00 2mo agoWhen properly configured, particularly at an enforcement policy of p=quarantine or p=reject, DMARC can positively impact inbox placement. https://mxtoolbox.com/dmarc/details/email-deliverability https://mxtoolbox.com/dmarc/details/email-deliverability
- inigyou 2mo agomxtoolbox isn't an email service provider. What email service provider does this?
- Freebytes 2mo agohttps://powerdmarc.com/gmail-enforcement-email-rejection/ https://powerdmarc.com/gmail-enforcement-email-rejection/
- account42 2mo ago> DMARC Policy > Requirement: Must exist (minimum p=none) This doesn't support ggp's claim.
- bawolff 2mo agoDMARC is essentially an opt-in to strict mode. Primarily it prevents other people from forging email to look like it is coming from you. The goal of dmarc is to prevent other people from impersonating you.
- Freebytes 2mo agoSome large companies have started blocking domains that do not have DMARC. It is a simple DNS entry. (Easier than SPF.) You should add it to all of your domains even though it accomplishes very little other than meeting the requirements of some larger companies.
- tgv 2mo agoThe article speaks about DMARC monitoring, but not about "writing" it. So many orgs are too small to have someone paying attention of these things. Where I work, the CTO used to manage the DNS, but with very little understanding of what it all means. It was just copy and paste. And yes, it also says p=none. Probably because it was in the example. It's like setting up a website for your company, and picking some wordpress instance: how are you supposed to know the risks? It's just too much.
- infogulch 2mo agoLLMs are very good at helping you manage DMARC/DNS related configuration, even as a non-expert. I used it to develop custom DMARC report processing app that: 1. sucks in reports sent to our dmarc inbox into a sqlite db, 2. displays the results in a web page. The reports queue up in the mailbox and I open and start the app once a month to check the status. The agent also also reviewed the state of email-related DNS records, describe what needs to change, including how and why, and verify changes after the fact to ensure they are correct. Some changes I made at the direction of an agent: fix domainkeys CNAMEs for M365, rotate M365 dkim keys that haven't been rotated for over a decade, fix broken spf record formatting. My biggest issue is that squarespace refuses to enable dkim signing for transactional emails that they send for us (order/shipping confirmation etc). The email sending service they use (socketlabs) supports it but they are not interested in enabling the feature, so I can't lock down our dmarc. I guess that means squarespace is not a good fit for our needs; it's just disappointing that we have to move to a different platform again for technical reasons that are solvable with a dashboard switch.
- tgv 2mo agoSounds nice, but it adds to the load. Small businesses consider their direct customers much more important, and have little time for this kind of thing. Managing a domain is more work than godaddy makes you believe...
- Geezus_42 2mo agoSPF, DKIM, and DMARC are not hard. It's literally just publishing data you should already have, a list of your sending IPs, a pubkey, and how to reach you.
- jwr 2mo agoI really think we should be solving a much bigger problem of the major email providers not providing an automated way of handling abuse and not caring about abuse reports at all. Most of my spam comes from the three major email providers and at this point I gave up even trying to send abuse reports because they just get ignored. The big companies do not have to care because nobody will block Google, Microsoft or Amazon. They are too big to fail. Spoofing a From field is an insignificant problem in comparison.
- cube00 2mo agoIt's ironic that I set everything up correctly on my self hosted domain and still end up in spam because of my low volume. I even go to the trouble of registering in their Postmaster Tools and clogging up my DNS with their verification tokens all for the tools to tell me I don't send enough mail while they happily pass what little mail I send straight to spam. Not enough outgoing email You haven't sent enough email to personal Gmail (@gmail.com) accounts to determine deliverability status for your domain and messages. Each screen only shows: "No data was found for this domain." Guess it doesn't help that as I look today the Postmaster Tools dashboard shows "Last updated Sun, Apr 26, at 9:30 AM." Then on the other hand Google can flood me with spam filled Google Calendar Invites and Google Drive Share notifications, all fully DKIM signed because they are coming out of those services, all day long. Microsoft have also recently changed their Smart Network Data Service (SNDS) so now only my cloud provider can access the console as they only allow verification to the owner of the whole ASN block you're under. I can't access detail about my domain anymore, and still my mail goes to junk. Unless you own a chunk of IPv4 ASN range you're out of luck. IPv6? Nope, not at Microsoft. "Please note that IPv6 is not currently supported." [1] [1]: https://substrate.office.com/ip-domain-management-snds/SNDS/AddNetwork https://substrate.office.com/ip-domain-management-snds/SNDS/...
- butterknife 2mo agoIn the same boat here. At least still have a good standing at Microft. Lost goodwill at big G by what I vaguely narrowed down to self hosted images in e-mail signature.
- nextblock 2mo ago[flagged]
- nubinetwork 2mo agoI'll set up DMARC after I get DKIM working... migrating my homelab has been taking forever...
- talkingtab 2mo agoEmail has been turned into a by-the-corporation, for-the-corporation service. Corporations need DMARC so they can control email and the ability to spam. The spam I cannot block is spam from Google. If you decide to think about this, you will quickly realize that email is f*ked and needs to be forked. Perhaps we need a Community Email Initiative that blocks corporations and only allows Community members. Trust is the one thing you can't buy on the Corporate Internet. I am sure many people will be offended and down vote this comment because they cannot conceptualize an internet without Corporations.
- baron3dl 2mo agoYou can do this right now, and you don't even need to fork anything. E-mail is an internet scale protocol that's not owned or ownable, except by convention. Since you specifically want to cut out Google, and their attempts to capture E-mail are what makes rolling your own E-mail hard anyway, just go for it. Depending on how hard you want to make it, you can slap all the parts together yourself or use something like Zimbra, Mailcow, iRedMail, mail-in-a-box. The advantage over a fork, whatever specifically that means, is any service that needs E-mail as an identity verification, still works.
- talkingtab 2mo agoWhat I am proposing is that community email servers can talk to each other. I have email servers setup - all the hoops - for my community. I want others to set up community servers and be able to interoperate. My server can send and receive from other communities. No corporations, no tracking. If your sever spams it gets dropped from the federation. Yes it is more complex, and there will be problems and issues. But hey, if we can have crypto currency why can't we get emails?
- baron3dl 2mo agolet's say this federation has three communities, a, b, and c. you run a, I run b, and my spammy friend runs c. C is my friend, and I'm going to keep allowing him to send me email, but you drop him, because he spammed you. that's literally how email works today, unless the federation can supersede my authority as an operator to choose who may send/receive with me, at which point it'd stop being a federation anyway.
- rft 2mo agoArticle is missing a note on the existence of MX records for the domains. Sure, you can easily have a send-only domain without an MX record, but the common case is likely to setup both send and receive capability. It would be interesting to have that number included as domains without MX and DMARC might just not be configured for email at all. Worst case the 45% of domains without DMARC are simply not relevant for email and thus not configured at all. I would find "x% of domains with configured email don't enforce DMARC" more interesting.
- datakan 2mo ago68.4% is actually a lot. Considering how badly abused email has always been, I'm actually surprised its nearly 70% and growing. Cup half full I guess
- OJFord 2mo ago68.4% still don't enforce it, i.e. adoption is just over 30%, not nearly 70%.
- datakan 2mo agoThank you
- bornfreddy 2mo agoYou misunderstood, it's 31.6% actually.
- datakan 2mo agoThank you
- TheChaplain 2mo agoIf you have any domains that does not use email, it may be a good idea to set up some DNS records to prevent it being used. DNS SPF record: mydomain.io. TXT "v=spf1 -all" DNS DMARC: _dmarc.mydomain.io. TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s" That ought to stop anyone trying to use your domains as source.
- newsoftheday 2mo agoI use postfix and the recipient_access file to control email to my domains which use little email, so the domains are able to process standard email: admin@example.com OK postmaster@example.com OK abuse@example.com OK webmaster@example.com OK hostmaster@example.com OK info@example.com OK example.com REJECT example.com
- teddyh 2mo agoAlso consider (using your example domain): *.mydomain.io. TXT "v=spf1 -all" to restrict SPF on all subdomains.
- auscompgeek 2mo agoSpecifying sp=reject in a DMARC policy would have a similar effect right?
- teddyh 2mo agoThe wildcard DNS SPF record is useful for mail receivers who won’t check DMARC, but will check SPF records. Also, the DMARC sp= setting defaults to the same as the p= setting (unless the DMARC record is itselt on a subdomain, in which case the sp= setting is ignored). So if you already have a strict p=reject setting, the sp= setting is useless.
- brightball 2mo agoYes! IMHO every registrar should be turning this on by default. Every DNS should do this by default until the owner explicitly turns on email sending. It would solve a lot of issues globally.
- EvanAnderson 2mo agoI mind email for a number of small orgs (<1000 recipients each). There are so many SPF and DKIM failures from senders who you'd think would know better (Fortune 100-type companies). I don't want complaints from users missing messages so I end up disregarding failures even when published policy says to do otherwise.
- velcrovan 2mo agoI take the opposite approach, I refuse to whitelist domains. When someone internal complains I send a notice to their contact on the other end (CCing the internal recipient) saying their email is misconfigured and ask them to put me in touch with their IT department to help them fix it. I use a script to do some DNS lookups and write the email for me. I have about a 50% success rate getting them to fix it.
- EvanAnderson 2mo agoMy spirit was broken for that kind of work a long time ago. More often than not I end up talking to someone in the sender's IT who fancies themself an expert and is completely incredulous that there could possibly be a problem on their side ("But we don't have problems sending email to anybody but you...") I should want to fight the good fight, but it's so demoralizing. Edit: Dealing with other IT people on problems like this taught me a ton of humility. It wasn't until I was in my early 30s before I'd reached a level of maturity to approach trouble reports like this being reported to me with an open mind. Before that I fancied myself and expert and, likely, was insufferable in many contexts. Now I'm insufferable in fewer contexts.
- account42 2mo agoWhat happens in the other 50%? Your users work around you somehow?
- Geezus_42 2mo agoFalls outside scope. Only half joking. If you can't figure out SPF/DKIM then you should find a new job.
- ButlerianJihad 2mo agoUsing DMARC information is complicated in practice in the real world, by Chris Siebenmann https://utcc.utoronto.ca/~cks/space/blog/spam/DMARCPracticalComplexity https://utcc.utoronto.ca/~cks/space/blog/spam/DMARCPractical...
- inigyou 2mo ago403 error
- damonblue 2mo ago[dead]
- sharpnick 2mo ago[flagged]
- bcrl 2mo agoSadly the article doesn't really touch on whether or not DMARC accomplishes anything truly useful. When I enabled DMARC for ingress email on one of my own mail servers, it ultimately ended up regularly blocking a handful emails from customers, yet virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks. The core problem is that the real need of email end users need is a way of determining whether or not to trust a given sender. Signatures are purely a technical measure which provides no information on the trustworthiness of the sender. The end result is that email scoring still has to be content based, and the signature check technologies are pure noise with no useful signal for the purpose of determining if an email should actually show up in my inbox. The tech industry has a bad habit of providing solutions to problems adjacent to problems the user actually needs solved while leaving the user's actual problem unresolved.
- bawolff 2mo ago> The core problem is that the real need of email end users need is a way of determining whether or not to trust a given sender. Which is only the core problem because dmarc fixed the other core problem of figuring out who the given sender is. DMARC does not solve everything, but it does make other solutions more effective.
- deknos 2mo ago> Which is only the core problem because dmarc fixed the other core problem of figuring out who the given sender is. Does it verify the sender or the domain/service which the sender is using?
- vandyswa 2mo agoDMARC, just like SPF before it, solves nothing. The spammers adapt. And unlike SPF, DMARC has an enormous technology surface area. Its failure modes are legion, and each one is tedious to run down to resolution. Which just returns you to something which never pays the rent anyway.
- BenjiWiebe 2mo agoOne awesome thing that SPF/DKIM/DMARC did... Now that spammers have "adapted", it means they can't say their email is from @mybank.com, or @microsoft.com, or @facebook.com, etc!
- inigyou 2mo agoExactly. This is a very important step. The fact that it did not stop spam is irrelevant.
- Freebytes 2mo agoSPF did solve an issue. Domain impersonation is no longer as much of an issue if you are strict against SPF failures. DMARC, on the other hand, solved absolutely nothing.
- sebow 2mo agoDMARC is simple in theory but quite tricky in practice (with subdomains, for example). You follow the guide for a service (say Mailgun, for example) and everything looks fine, but CloudFlare shows up issues. You fix those issues and you're conflicting the mail service guide. Anyways, the new CF AI tool is relatively decent for this purpose, explains the fact that most warnings in CF are harmless, but the lack of standardized guidelines is annoying to say the least.
- raluk 2mo agoI am running email server for my private domain using https://github.com/docker-mailserver/docker-mailserver https://github.com/docker-mailserver/docker-mailserver . One day in 2023 i decided that beside of dkim i maybe should also enable dmarc. Because ... well, why not. What happened was that i started reciving regular reports over email from ms and google containing compressed xml containing no info other that empty report was generated. What should I do with that? At that time i could not find any tool that would be able to extract valuable info from that, so I disabled dmarc. Havent looked back since.
- matharmin 2mo agoThere are lots of free tools that automatically analyze the reports for you (you send it to them, instead of yourself). But if you send all emails for your domain from one email server, you could just disable rua reporting. The reports are mainly useful to see whether you have some misconfigired email server somewhere that causes (or will cause) dropped emails. That can easily happen if you send some email from your own server, some via sendgrid, some via some marketing tool, and start to lose track of them. But for a personal email server, that's not common.
- toast0 2mo agoThe reports are kind of useful when first enabling, if you want to get warnings about non-compliant mail, but after you're established, they're not really useful, so you should turn reports off, but you can do that without turning off the whole thing.
- thyristan 2mo agoDomains with stricter DMARC that isn't on 'none' are in my experience more likely to be spammers than desirable email.
- at1as 2mo agoI’d be interested these stats broken down between domains associated with operating companies and personal or hobby domains. The latter are likely to adopt much more slowly simply because of less perceived risk, lower payoff (no vendor reviews), and less dedicated technical expertise. Just like personal sites were slow to adopt HTTPS. Mass HTTPS adoption happened once browser warnings and SEO incentives rendered sites mostly useless without it.
- account42 2mo agoI'd expect the opposite really. Personal domains sending email are more likely to be run by MTA enthusiasts who don't have any money riding on others being able to receive their mails compared to corporate IT where mail is just one more thing they have to wrangle and really don't need the company leadership being angry at them because the spam-as-a-service company that marketing has been using without telling anyone gets blocked due to their DNS settings.
- inigyou 2mo agoMass HTTPS adoption happened when it stopped costing $100 every year and requiring three forms of KYC, which is after Snowden showed us why we really should be using it all the time.
- TonyTrapp 2mo agoI have set up DMARC, SPF, DKIM and whatnot. Sadly no one seems to take this as a signal for a competent mail setup, so Microsoft's mail servers regularly block my mails because of the surrounding IP range reputation - not because any spam would originate from my IPs or domains.
- inigyou 2mo agoAre you sending important or unimportant things? When its unimportant or important to the receiver only, you push responsibility to them: "I sent it. Must be your email that's glithced. Tried Gmail or Proton?" When its important to you, you use your backup Gmail or Proton account.
- luciana1u 2mo ago[flagged]
- thomas_krosos 2mo ago[flagged]
- agotterer 2mo agoI didn't see it explicitly mentioned in the post, I wonder if they filtered exclusively for domains with mx records. Because I would assume that lots of domains just don't have email configured and therefore aren't aware that you should still setup DMARC to prevent impersination of your domain.
- ovo101 2mo ago[flagged]
- tailscaler2026 2mo ago[dead]
- landver 2mo ago[flagged]
- asimops 2mo agoThe domains that do enforce DMARC are apparently configured so badly that the German secure email provider mailbox.org decided not to honor DMARC. See this thread in German: https://userforum.mailbox.org/topic/10676-mailbox-org-akzeptiert-gefalschte-mails-trotz-spf-fail-dkim-fail-dmarc-fail-und-reject-policy https://userforum.mailbox.org/topic/10676-mailbox-org-akzept...
- usr1106 2mo agoInteresting thread. However, for over a year, the "secure email provider" did not reply more than that the consultants are too overloaded to reply... The message you obviously refer to as just an educated guess by a forum user who seems to be experienced in email topics. It could be that the guess is correct. It could be hat the consumtants are too overloaded to configure things differently. Another user has that guess. We don't know as long as the provider does not answer.
- PunchyHamster 2mo agoGiven how much spam has valid DMARC/DKIM it is just useless. Turns out making absolutely sure email isn't faked means jack shit if user isn't even looking at it, or the spoofed domains looks "close enough". Currently the big pile of mail "security" extensions is basically useless pile of waste that just gives mail server admins some extra work.
- Lookbefore-org 2mo ago[dead]
- cheema33 2mo agoAt our small 12-person company, I help manage DNS. Email service is through Microsoft. I had previously configured SPF and DKIM etc. but never DMARC. We are too small to have time for everything. But, I recently asked Claude to review the entire config and recommend changes. It suggested DMARC. I said, "implement it". And it did. It does have access to our Cloudflare/DNS account and make changes using terraform/opentofu in a way that allows me to review the changes before they are made. LLMs are great for this sort of thing that used to be a massive pain in the rear.
- fdcampbell 2mo ago[flagged]
- mvg777 2mo ago[flagged]