logoalt Hacker News

DMARC has been public since 2012 but most company domains still don't enforce it

160 pointsby aduliontoday at 10:20 AM100 commentsview on HN

Comments

bcrltoday at 2:09 PM

Sadly the article doesn't really touch on whether or not DMARC accomplishes anything truly useful. When I enabled DMARC for ingress email on one of my own mail servers, it ultimately ended up regularly blocking a handful emails from customers, yet virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks.

The core problem is that the real need of email end users need is a way of determining whether or not to trust a given sender. Signatures are purely a technical measure which provides no information on the trustworthiness of the sender. The end result is that email scoring still has to be content based, and the signature check technologies are pure noise with no useful signal for the purpose of determining if an email should actually show up in my inbox.

The tech industry has a bad habit of providing solutions to problems adjacent to problems the user actually needs solved while leaving the user's actual problem unresolved.

show 7 replies
EvanAndersontoday at 1:52 PM

I mind email for a number of small orgs (<1000 recipients each). There are so many SPF and DKIM failures from senders who you'd think would know better (Fortune 100-type companies). I don't want complaints from users missing messages so I end up disregarding failures even when published policy says to do otherwise.

show 1 reply
TheChaplaintoday at 1:51 PM

If you have any domains that does not use email, it may be a good idea to set up some DNS records to prevent it being used.

DNS SPF record: mydomain.io. TXT "v=spf1 -all"

DNS DMARC: _dmarc.mydomain.io. TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s"

That ought to stop anyone trying to use your domains as source.

show 3 replies
tgvtoday at 12:59 PM

The article speaks about DMARC monitoring, but not about "writing" it. So many orgs are too small to have someone paying attention of these things. Where I work, the CTO used to manage the DNS, but with very little understanding of what it all means. It was just copy and paste. And yes, it also says p=none. Probably because it was in the example. It's like setting up a website for your company, and picking some wordpress instance: how are you supposed to know the risks? It's just too much.

show 1 reply
talkingtabtoday at 1:31 PM

Email has been turned into a by-the-corporation, for-the-corporation service. Corporations need DMARC so they can control email and the ability to spam. The spam I cannot block is spam from Google.

If you decide to think about this, you will quickly realize that email is f*ked and needs to be forked. Perhaps we need a Community Email Initiative that blocks corporations and only allows Community members.

Trust is the one thing you can't buy on the Corporate Internet.

I am sure many people will be offended and down vote this comment because they cannot conceptualize an internet without Corporations.

show 5 replies
jwrtoday at 1:19 PM

I really think we should be solving a much bigger problem of the major email providers not providing an automated way of handling abuse and not caring about abuse reports at all. Most of my spam comes from the three major email providers and at this point I gave up even trying to send abuse reports because they just get ignored.

The big companies do not have to care because nobody will block Google, Microsoft or Amazon. They are too big to fail.

Spoofing a From field is an insignificant problem in comparison.

show 3 replies
asimopstoday at 7:38 PM

The domains that do enforce DMARC are apparently configured so badly that the German secure email provider mailbox.org decided not to honor DMARC.

See this thread in German: https://userforum.mailbox.org/topic/10676-mailbox-org-akzept...

agotterertoday at 4:18 PM

I didn't see it explicitly mentioned in the post, I wonder if they filtered exclusively for domains with mx records. Because I would assume that lots of domains just don't have email configured and therefore aren't aware that you should still setup DMARC to prevent impersination of your domain.

TonyTrapptoday at 3:25 PM

I have set up DMARC, SPF, DKIM and whatnot. Sadly no one seems to take this as a signal for a competent mail setup, so Microsoft's mail servers regularly block my mails because of the surrounding IP range reputation - not because any spam would originate from my IPs or domains.

raluktoday at 2:26 PM

I am running email server for my private domain using https://github.com/docker-mailserver/docker-mailserver . One day in 2023 i decided that beside of dkim i maybe should also enable dmarc. Because ... well, why not. What happened was that i started reciving regular reports over email from ms and google containing compressed xml containing no info other that empty report was generated. What should I do with that? At that time i could not find any tool that would be able to extract valuable info from that, so I disabled dmarc. Havent looked back since.

show 2 replies
nubinetworktoday at 1:28 PM

I'll set up DMARC after I get DKIM working... migrating my homelab has been taking forever...

vandyswatoday at 2:13 PM

DMARC, just like SPF before it, solves nothing. The spammers adapt. And unlike SPF, DMARC has an enormous technology surface area. Its failure modes are legion, and each one is tedious to run down to resolution. Which just returns you to something which never pays the rent anyway.

at1astoday at 3:16 PM

I’d be interested these stats broken down between domains associated with operating companies and personal or hobby domains.

The latter are likely to adopt much more slowly simply because of less perceived risk, lower payoff (no vendor reviews), and less dedicated technical expertise.

Just like personal sites were slow to adopt HTTPS. Mass HTTPS adoption happened once browser warnings and SEO incentives rendered sites mostly useless without it.

show 1 reply
rfttoday at 1:35 PM

Article is missing a note on the existence of MX records for the domains. Sure, you can easily have a send-only domain without an MX record, but the common case is likely to setup both send and receive capability. It would be interesting to have that number included as domains without MX and DMARC might just not be configured for email at all. Worst case the 45% of domains without DMARC are simply not relevant for email and thus not configured at all. I would find "x% of domains with configured email don't enforce DMARC" more interesting.

show 1 reply
smartmictoday at 12:55 PM

I am self-hosting my (secondary) email and have only implemented SPF and DKIM. This works fine on a practical level for me. What would be the benefit of setting up DMARC on top?

show 4 replies
PunchyHamstertoday at 8:26 PM

Given how much spam has valid DMARC/DKIM it is just useless.

Turns out making absolutely sure email isn't faked means jack shit if user isn't even looking at it, or the spoofed domains looks "close enough".

Currently the big pile of mail "security" extensions is basically useless pile of waste that just gives mail server admins some extra work.

thyristantoday at 2:36 PM

Domains with stricter DMARC that isn't on 'none' are in my experience more likely to be spammers than desirable email.

datakantoday at 1:41 PM

68.4% is actually a lot. Considering how badly abused email has always been, I'm actually surprised its nearly 70% and growing. Cup half full I guess

show 2 replies
ButlerianJihadtoday at 1:54 PM

Using DMARC information is complicated in practice in the real world, by Chris Siebenmann

https://utcc.utoronto.ca/~cks/space/blog/spam/DMARCPractical...

sebowtoday at 2:16 PM

DMARC is simple in theory but quite tricky in practice (with subdomains, for example). You follow the guide for a service (say Mailgun, for example) and everything looks fine, but CloudFlare shows up issues. You fix those issues and you're conflicting the mail service guide.

Anyways, the new CF AI tool is relatively decent for this purpose, explains the fact that most warnings in CF are harmless, but the lack of standardized guidelines is annoying to say the least.

landvertoday at 7:26 PM

[flagged]

thomas_krosostoday at 3:57 PM

[flagged]

ovo101today at 4:50 PM

[flagged]

nextblocktoday at 1:26 PM

[flagged]

sharpnicktoday at 2:02 PM

[flagged]

tailscaler2026today at 5:08 PM

[dead]

luciana1utoday at 3:44 PM

[dead]

damonbluetoday at 2:02 PM

[dead]