Skip to Content.
Sympa Menu

cacert-sysadm - Re: Violations in DMARC Aggregate Report

cacert-sysadm AT lists.cacert.org

Subject: CAcert System Admins discussion list

List archive

Re: Violations in DMARC Aggregate Report


Chronological Thread 
  • From: "Disch, Uwe (Disch Engineering™)" <uwe.disch AT disch-online.de>
  • To: cacert-sysadm AT lists.cacert.org
  • Subject: Re: Violations in DMARC Aggregate Report
  • Date: Sun, 16 Nov 2014 19:35:20 +0100
  • Domainkey-signature: a=rsa-sha1; c=simple; d=disch-online.de; h= message-id:date:from:mime-version:to:subject:references :in-reply-to:content-type; q=dns; s=default; b=jx2Gvc298J/JvqLHf JsQSDZcJNqPQj1PnOktICvcGDvgk83wHb+K5B9ALtit/aVqxwzUtVRvfUmSqwCGV CVOQQ4+c4LJiAdk8/cOy00FuqNoKNvfOMjaTimLhQF4HQ1zy/H175l/5G7C2Xx8g a/7CUpNo4GWLbBPVcAzp7WKGSU=
  • Organization: Disch Services GmbH

Hi,

Am 16.11.2014 um 00:32 schrieb Benny Baumann:
Hi Mario,

Am 15.11.2014 um 12:00 schrieb Mario Lipinski:
Hi Uwe,

imho you should not set '-all' for domains you are using for services
that include mail redirection, such as mailing lists.

An even better practice is Sender Rewriting on the part of the mailing
list server, thus the envelope sender of the mail originating from the
mailing list becomes CAcert and thus the CAcert ML SPF records apply.
It's a known problem with SPF deployment but hardly ever addressed anywhere.
Yes, this was in my mind when I sent my initial post.  Please see:
https://en.wikipedia.org/wiki/Sender_Rewriting_Scheme

For example Google is using SRS.  Patched qmail also.

And with this DMARC and SPF stuff I know who is trying to abuse my domains...
Mario

Regards,
BenBE.
Bye
Uwe
Am 15.11.2014 11:25, schrieb "Disch, Uwe (Disch Engineering™)":
the actual setup of the list servers of cacert.org violates DMARC.

The list mail servers should not send e-mails for which them not
authorized to do so (mainly SPF rule violation).  See attachments for
more info.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature




Archive powered by MHonArc 2.6.18.

Top of Page