logoalt Hacker News

What DMARC Protects You From, and What It Does Not

123 pointsby aduliontoday at 9:29 AM29 commentsview on HN

Comments

sam_lowry_today at 10:15 AM

> Every email carries two "from" addresses

I made a presentation about exactly the same subject many years ago, but I was not shy of separating the SMTP protocol (RFC 821 and the following ) and the email message (RFC 822 and the following).

It makes the link between SPF, DKIM and DMARC much clearer.

Anyway. The article covers just the bare minimum, and in the most obscure way.

For those interested in the inner workings of contemporary email delivery... I recommend the posts by Alex Shakhov on LinkedIn https://www.linkedin.com/in/alexshakhov/ (Yes, there is still meaningful content on LinkedIn, it's just vanishingly rare)

aviantoday at 10:55 AM

Vaguely related question: what is the go-to open DMARC check implementation these days? I mean the part that checks _received_ mail against DMARC rules. It used to be opendmarc, but it seems people have been dropping it for a while because of history of breaking changes and general lack of good stewardship [1]. Anyone using pydmarc [2]?

It's hard to find good info on this since 99% of search hits are people talking about setting up DMARC from the _sender_ side.

[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1014058#39

[2] https://pypi.org/project/dmarc/

show 3 replies
joladevtoday at 11:52 AM

> Here is the part that trips people up.

It's hard to take something seriously when it's very clearly AI generated. It's just a coin toss on whether the information in the article is correct.

show 1 reply
crossroadsguytoday at 7:13 PM

> Where it falls short

Really? DMARC falls short there? "DMARC" now must run around beating any naughty sender that tries to send spoofed email with a stick? Because it already proves they're a spoofer (if domain owner was smart/important enough) to anyone who is looking :)

I had set the rules to reject the mail (if someone tried to spoof my personal domain; some do) and then send me a combined report. After realising I could do nothing with those reports, I just removed that part.

Anyway, one of the few reasons I still use Thunderbird is its DKIM Verifier add-on.

SMS and email, in their current design, have outlived their safety relevance by a long shot. At least email has some protections (or a lot), but SMS is just a time bomb that keeps getting used even though it keeps going off.

thesuitonymtoday at 6:33 PM

Bad article, probably a bad product.

show 1 reply
PunchyHamstertoday at 5:05 PM

protests you from: having some free time for more important things

doesn't protect you from: anything, users will get phished by domain anyway, and the spammers/scammer send DMARCed email anyway

show 1 reply
sourcecodeplztoday at 5:40 PM

dmarc

sylwaretoday at 11:05 AM

I think DMARC is missing email address with IPv[46] literals support. As being self-hosted, without paying the DNS mob, I am still blocked to send email to gmail.com because such email addresses do throw out of whack gogol code.

Email addresses with IPv[46] literals are intrinsincly stronger than SPF. If in the envelope or any of the 'from' headers (if my memory does not fail me, there are few more headers to scan), the IPv[46] literal does not match the actual and real IP of the SMTP server, the email is dropped, not even going into any spam folder.

Conspiracy mode: they know and are careful not to support that, in order to create a walled garden of internet messaging for them and their friends.

show 4 replies
ShieldScopeApptoday at 2:06 PM

[flagged]

effnorwoodtoday at 12:48 PM

[dead]

cadamsdotcomtoday at 10:11 AM

Dear author:

Do NOT ship your first draft!

This piece is a great example of writing smells - you do a disservice to humanity by leaving such important information typed up so awfully.

For instance. "This matters" is a writing smell that stinks to high heaven. Just like code smells - hints that something is off about the code. Can't quite tell something is wrong but you don't like it. Spider sense tingling. Same for bad writing - there are huge signposts you can easily rip out.

If you had to tell us a thing matters you've made TWO MISTAKES. One, you left in whatever it was that didn't matter, so now you gotta tell people hey ignore that stuff! Look at this stuff over here! - and two, you also left in the assertion that this or that thing matters! Delete the shit that didn't matter, then delete the assertion that the thing that matters matters! Poof! Gone! See how nicely it reads now? Spend those 10 words elsewhere with a better payoff.

Smelly writing is no fun to read, and it's rude to ship your first draft.

show 2 replies