Hacker News
What DMARC Protects You From, and What It Does Not
sam_lowry_
|next
[-]
I made a presentation about exactly the same subject many years ago, but I was not shy of separating the SMTP protocol (RFC 821 and the following ) and the email message (RFC 822 and the following).
It makes the link between SPF, DKIM and DMARC much clearer.
Anyway. The article covers just the bare minimum, and in the most obscure way.
For those interested in the inner workings of contemporary email delivery... I recommend the posts by Alex Shakhov on LinkedIn https://www.linkedin.com/in/alexshakhov/ (Yes, there is still meaningful content on LinkedIn, it's just vanishingly rare)
ddevnyc
|root
|parent
|next
|previous
[-]
sam_lowry_
|root
|parent
[-]
https://mikhailian.mova.org/delivering-mails/1.png shows the SMTP plaintext chat for the first case,
https://mikhailian.mova.org/delivering-mails/2.png shows the second.
philosopherNoob
|root
|parent
|previous
[-]
sam_lowry_
|root
|parent
[-]
avian
|next
|previous
[-]
It's hard to find good info on this since 99% of search hits are people talking about setting up DMARC from the _sender_ side.
[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1014058#39
oogali
|root
|parent
|next
[-]
This might be a little heavy if you’re solely looking for DMARC validation, but I use the other parts of rspamd as well for inbound email.
https://rspamd.com/modules/dmarc/
For a library, I mainly write Go and I use https://github.com/emersion/go-msgauth (formerly known as go-dkim).
actionfromafar
|root
|parent
[-]
joladev
|next
|previous
[-]
It's hard to take something seriously when it's very clearly AI generated. It's just a coin toss on whether the information in the article is correct.
crossroadsguy
|next
|previous
[-]
Really? DMARC falls short there? "DMARC" now must run around beating any naughty sender that tries to send spoofed email with a stick? Because it already proves they're a spoofer (if domain owner was smart/important enough) to anyone who is looking :)
I had set the rules to reject the mail (if someone tried to spoof my personal domain; some do) and then send me a combined report. After realising I could do nothing with those reports, I just removed that part.
Anyway, one of the few reasons I still use Thunderbird is its DKIM Verifier add-on.
SMS and email, in their current design, have outlived their safety relevance by a long shot. At least email has some protections (or a lot), but SMS is just a time bomb that keeps getting used even though it keeps going off.
PunchyHamster
|next
|previous
[-]
doesn't protect you from: anything, users will get phished by domain anyway, and the spammers/scammer send DMARCed email anyway
sylware
|next
|previous
[-]
Email addresses with IPv[46] literals are intrinsincly stronger than SPF. If in the envelope or any of the 'from' headers (if my memory does not fail me, there are few more headers to scan), the IPv[46] literal does not match the actual and real IP of the SMTP server, the email is dropped, not even going into any spam folder.
Conspiracy mode: they know and are careful not to support that, in order to create a walled garden of internet messaging for them and their friends.
lxgr
|root
|parent
|next
[-]
PunchyHamster
|root
|parent
|next
|previous
[-]
kube-system
|root
|parent
|previous
[-]
cadamsdotcom
|previous
[-]
dspillett
|root
|parent
|next
[-]
To whom this should concern:
Oh, do pop off.
Bothering to write/edit anything yourself should be given bonus points these days, not pulled apart for minor grammar/structural/style issues. You'll be telling me no to flaming split initiatives next.