Live data from Hacker News

What DMARC Protects You From, and What It Does Not

senderledger.com

31–40 of 47 posts

Re: What DMARC Protects You From, and What It Does Not

#33

protests you from: having some free time for more important things doesn't protect you from: anything, users will get phished by domain anyway, and the spammers/scammer send DMARCed email anyway

I'm not sure why you think DMARC takes a lot of time to manage. It doesn't. Are you trying to read every single RUA report daily?

Re: What DMARC Protects You From, and What It Does Not

#35

Bad article, probably a bad product.

Can you elaborate more on why it's a bad article?

Is someone who doesn't know much about it? It seem to make a lot of sense to me and was really easy to understand and digest.. is there something inaccurate about it though?

Re: What DMARC Protects You From, and What It Does Not

#36
> Where it falls short

Really? DMARC falls short there? "DMARC" now must run around beating any naughty sender that tries to send spoofed email with a stick? Because it already proves they're a spoofer (if domain owner was smart/important enough) to anyone who is looking :)

I had set the rules to reject the mail (if someone tried to spoof my personal domain; some do) and then send me a combined report. After realising I could do nothing with those reports, I just removed that part.

Anyway, one of the few reasons I still use Thunderbird is its DKIM Verifier add-on.

SMS and email, in their current design, have outlived their safety relevance by a long shot. At least email has some protections (or a lot), but SMS is just a time bomb that keeps getting used even though it keeps going off.

Re: What DMARC Protects You From, and What It Does Not

#37
post #6

I think DMARC is missing email address with IPv[46] literals support. As being self-hosted, without paying the DNS mob, I am still blocked to send email to gmail.com because such email addresses do throw out of whack gogol code. Email addresses with IPv[46] literals are intrinsincly stronger than SPF. If in the envelope or any of the 'from' headers (if my memory does not fail me, there are few more headers to scan),…

I think DMARC is missing support for homing pigeon characteristics such as the markings and colors on its crest and plumage. As being self-hosted, without paying the IANA and ISP mob, I am still blocked to send email to gmail.com.

Re: What DMARC Protects You From, and What It Does Not

#38
post #6

I think DMARC is missing email address with IPv[46] literals support. As being self-hosted, without paying the DNS mob, I am still blocked to send email to gmail.com because such email addresses do throw out of whack gogol code. Email addresses with IPv[46] literals are intrinsincly stronger than SPF. If in the envelope or any of the 'from' headers (if my memory does not fail me, there are few more headers to scan),…

It is not a conspiracy theory that it is hard to maintain reliable delivery with self-hosting email. It is primarily because email filters are in part based on trust relationships, and huge amounts of spam come (or at least, did) from relatively unknown originating servers.

Spam does not work with email addresses using IP literals.

Re: What DMARC Protects You From, and What It Does Not

#39
post #6

I think DMARC is missing email address with IPv[46] literals support. As being self-hosted, without paying the DNS mob, I am still blocked to send email to gmail.com because such email addresses do throw out of whack gogol code. Email addresses with IPv[46] literals are intrinsincly stronger than SPF. If in the envelope or any of the 'from' headers (if my memory does not fail me, there are few more headers to scan),…

I think DMARC is missing support for homing pigeon characteristics such as the markings and colors on its crest and plumage. As being self-hosted, without paying the IANA and ISP mob, I am still blocked to send email to gmail.com.

Regulation on small tech interop is exactly for guys like you.

Re: What DMARC Protects You From, and What It Does Not

#40

Earlier quoted context omitted.

Are those posts available without logging in? This sounds like good stuff but I can’t access it.

I think he reposts them on his consulting page https://www.sh.consulting/blog and no, I am not affiliated. Just keeping an eye on the email deliverability topic as a hoppy.

Do you mean as a hobby?
Post reply on HN