Live data from Hacker News

DMARC has been public since 2012 but most company domains still don't enforce it

ciphercue.com

121–130 of 185 posts

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#121

Earlier quoted context omitted.

Okay but that doesn’t detract from the intended purpose of DMARC.

Perfect example of "The Purpose Of A System Is What It Does."[1] 1: https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_wha...

That saying is bullshit. The purpose of a system is, by definition, what it is intended to do, not what it does. You can judge efficacy by the results, but not the purpose.

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#122

Earlier quoted context omitted.

> virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks. This should create a means to go after the domain owners via registrar and trail of ownership, even so far as blocking email from the domain. Forcing the spammers to pass DMARC creates a burden and an evidence trail that didn't exist before.

What spammers are using the same domain for longer than couple of hours? What do you expect to achieve by blocking an already abandoned domain?

@gmail.com and @outlook.com are like 90% of the spam I receive. What’s missing is effective accountability for those two companies hosting persistent spam groups who operate for months unimpeded.

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#123

Earlier quoted context omitted.

Perfect example of "The Purpose Of A System Is What It Does."[1] 1: https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_wha...

That saying is bullshit. The purpose of a system is, by definition, what it is intended to do, not what it does. You can judge efficacy by the results, but not the purpose.

[deleted]

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#124

The domains that do enforce DMARC are apparently configured so badly that the German secure email provider mailbox.org decided not to honor DMARC. See this thread in German: https://userforum.mailbox.org/topic/10676-mailbox-org-akzept...

Interesting thread. However, for over a year, the "secure email provider" did not reply more than that the consultants are too overloaded to reply...

The message you obviously refer to as just an educated guess by a forum user who seems to be experienced in email topics. It could be that the guess is correct. It could be hat the consumtants are too overloaded to configure things differently. Another user has that guess. We don't know as long as the provider does not answer.

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#125
post #28

Sadly the article doesn't really touch on whether or not DMARC accomplishes anything truly useful. When I enabled DMARC for ingress email on one of my own mail servers, it ultimately ended up regularly blocking a handful emails from customers, yet virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks. The core problem is that the real need of email end users need is a way o…

Stopping spam isn't what DMARC was designed for.

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#126
post #114

Earlier quoted context omitted.

If snail mail cost $0.001 per recipient people would be getting much, much more junkmail. Likewise, if e-mail cost as much as even bulk snail mail, there'd be much less spam. Some sort of payment scheme is really the best, most durable option. The problem of mailing-lists and personal correspondence could be solved by an exclusion mechanism where the recipient effectively whitelists senders, explicitly or implicitly…

The problem with a payment scheme is that spammers (who make money by spamming) will happily pay as a cost of doing business (or negotiate discounts/deals), but Joe User might just look at the cost and say, "you know what, maybe I'll send this as SMS instead of E-mail." So the end result will be more spam and fewer legit E-mails.

I've wondered if it cost $10 to get through my email box the first two times what they would mean.

Hormozi could charge $1,000 to get into his read box.

We could refund people, add them to a whitelist - and return a 405? payment required by default and things change in interesting ways when the amount is variable.

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#127
post #97

Earlier quoted context omitted.

Can we use DMARC to ask Gmail to close registrations? Google Calendar to allow far fewer people the ability to send invite notifications? Firebase to close registrations? Azure? Microsoft 365? AWS SES? It feels like the biggest spammers have swung back to just abusing SaaS and getting SPF / DKIM / DMARC for free from one of the big email providers.

Exactly this. Spammers have the technical competence to overcome any technical hurdle, so using evidence of technical competence achieves nothing. If it were possible to charge $0.25/email for delivery, I'd be more than happy . However, I'm sure large tech firms will need to say that is "too hard to implement at scale".

> If it were possible to charge $0.25/email for delivery, I'd be more than happy .

I'm baffled by this blend of replies. What exactly do you believe charging for an email would do? I mean, other than fabricating a revenue stream. Do you seriously believe that spam would vanish as soon as anyone charged for it's delivery? Because advertisers already pay for reaching their target audiences, and do so well beyond email.

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#128
post #110

Earlier quoted context omitted.

Stamp costs don't stop snail mail spam, either, unfortunately. I would be concerned if we added something like bitcoin fees to email delivery rather than curtail spam it would just further encourage grifters seeking ROI on their spam deliveries.

What if a single email cost $0.001 cent to send, and it was paid to the recipient? For $10, you could send 10,000 emails. For recipients, every 1,000 emails they get is a dollar in their wallet. You’d need something like a blockchain for this to work because the traditional payment processors still haven’t figured out micropayments.

> What if a single email cost $0.001 cent to send, and it was paid to the recipient? For $10, you could send 10,000 emails. For recipients, every 1,000 emails they get is a dollar in their wallet.

I'm not sure you realize your proposal's only contribution is to worsen spam. You are unwittingly creating an incentive for email providers to lift anti-abuse filters and to maximize the volume of spam delivered to you.

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#129
post #34
post #28

Sadly the article doesn't really touch on whether or not DMARC accomplishes anything truly useful. When I enabled DMARC for ingress email on one of my own mail servers, it ultimately ended up regularly blocking a handful emails from customers, yet virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks. The core problem is that the real need of email end users need is a way o…

> The core problem is that the real need of email end users need is a way of determining whether or not to trust a given sender. Which is only the core problem because dmarc fixed the other core problem of figuring out who the given sender is. DMARC does not solve everything, but it does make other solutions more effective.

> Which is only the core problem because dmarc fixed the other core problem of figuring out who the given sender is.

Does it verify the sender or the domain/service which the sender is using?

Re: DMARC has been public since 2012 but most company domains still don't enforce it

#130

Earlier quoted context omitted.

The problem with a payment scheme is that spammers (who make money by spamming) will happily pay as a cost of doing business (or negotiate discounts/deals), but Joe User might just look at the cost and say, "you know what, maybe I'll send this as SMS instead of E-mail." So the end result will be more spam and fewer legit E-mails.

I've wondered if it cost $10 to get through my email box the first two times what they would mean. Hormozi could charge $1,000 to get into his read box. We could refund people, add them to a whitelist - and return a 405? payment required by default and things change in interesting ways when the amount is variable.

There are platforms based on this idea: pay to reach a public person’s inbox, often with guaranteed responses (“guaranteed” as in “you get a response or you money back”). For example: https://mypublicinbox.com/en/
Post reply on HN