Skip to Content.
Sympa Menu

en - RE: [sympa-users] problems with DMARC?

Subject: The mailing list for listmasters using Sympa

List archive

Chronological Thread  
  • From: Steve Shipway <address@concealed>
  • To: "address@concealed" <address@concealed>
  • Subject: RE: [sympa-users] problems with DMARC?
  • Date: Fri, 25 Apr 2014 01:36:37 +0000

>I wonder how many mailers are going to attempt to deliver to the .invalid address when someone hits reply?

This shouldn't be a problem, since my patch sets Reply-To to be the original From, unless the list itself sets an explicit Reply-To without respecting existing.

>Also, will this invalidate the use of DKIM and DMARC by the mailing list itself?  I don't know enough about DKIM and how it's verified on the receiver to know which headers are checked against the domain selector in the DKIM signature itself.

No, DKIM signatures will be fine, since they don't care about the From address.  The *.invalid domains have no DNS entries and hence no DMARC records, so will never mandate the From domain matches the DKIM signing domain.

>What became of your "anonymising mode" idea?

Since Sympa already has an anonymising option, which takes care of some other headers as well, it would be redundant to add it here as well.  I envision having an option in the DMARC Protection section to choose if you want to use the original address with a  .invalid suffix, or the list email address in th4e From header.

> what about a "de-munger" to make list replies work. Something like

I think that Reply-To headers should take care of this so we don't need a complex redirect.

> Maybe just rewrite them all to a single address that is just configured
to reply with a notice saying "due to the DMARC policy of the domain of the
person you are trying to email your mail was not delivered, please adjust
the to address and try again".

The current patch can already do this; if you specify an explicit address for the from email, then this is used rather than the default of the list address.  So you can set it to the auto-reply email address simply enough.

I'm going to try and get access to the dmarc-discuss list archives to see what people have been saying about solutions for this.  It's probably too much to hope for that DMARC validation would be changed to match dkim signature domain against Sender when present rather than From....

Steve

Steve Shipway
University of Auckland ITS
UNIX Systems Design Lead
Ph: +64 9 373 7599 ext 86487




Archive powered by MHonArc 2.6.19+.

Top of Page