Live data from Hacker News

Spammers are better at SPF, DKIM, and DMARC than everyone else

toad.social

81–90 of 261 posts

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#81
honestly my take away is the opposite

we by far don't enforce them strict enough, because if we where people would make sure to get it right

it's all a question about effort/turnout

if you make it so that most times you mails still somehow end up with the user even if you mess them up there is much less insensitive for companies to fix their mail or force their provider to fix it

so IMHO if all of SPF,DKIM and DMARC are not correct setup mails should just be directly discarded and not even delivered to spam

while being more flexible was reasonable when this tech was new, that was 10 years ago. If being flexible mean that you also will sometime deliver outright cyber attacks like spear phishing and similar to your user and everyone had 10 years to fix their systems then there is really no reason to still be flexible.

Also "scammers get it right so it's useless" is such a huge red hearing argument, yes they do get it right _for their domains_. It sill makes it harder (and if strictly enforced impossible, except if you give them permissions to do that*) for them to impersonate your domains.

And yes that doesn't fix scammers from using their own domains, but it also was never intended to do so. Doing so is a very different problem one which probably needs some form of reputation system which isn't something you can just solve technically as it touches on a lot of subtle social political issues. Also given that all of the huge mail vendors have insensitive to use their "intern proprietary obscure" reputation system I don't expect there to be a technical solution provided/adopted tbh.

(and yes SPF/DKIM/DMARC are all tech wise quite "meh", but we are kinda stuck with them, through that never was the issue IMHO, the issue is missing insensitive to bring the adoption up and missing insensitive for large mail providers to enforce it strictly)

EDIT: PS: In one point they are fully right so, that is, with how things are you can't give SPF/DKIM/DMARC a large weight for calculating reputation. Also they where always only meant to tell you if someone can't be trusted, but never if someone can be trusted.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#82
post #55

Earlier quoted context omitted.

> That implies that we have some work to do on the problem of identity. As it is, there is not even a way for a known email sender to securely introduce an unknown email sender. There is: gpg/pgp signature, but many people find it complicated, primarily because they are reluctant to read the documentation. And it’s popular to criticize it, especially here on HN, in favor of various half-baked alternatives.

I think everyone can agree that any technology that "isn't complicated if you read the documentation" is by definition complicated. I don't need to read the documentation for Gmail to use Gmail successfully. Could I, as a trained programmer, use PGP and GPG? I'm sure I could if I spent some time reading about it. Could my 90 year old grandmother, who is otherwise quite comfortable with email and whatsapp? No, not to…

I highly disagree with this.

I just left a couple of comments regarding the use of "strtok". Its use is straightforward, just RTFM. Those were the golden days when people were less reluctant to read documentation. You could not even install Linux back then without an installation guide of some sort. You still need it for Gentoo, perhaps even Arch or Void. Are they wrong? No, just different target audience. If you do not want to become a "power user", that is fine.

My grandma can barely handle the TV controller. So what? I am really against dumbing things down, called "ease-of-access" or whatever they call it these days.

I agree on that, however, that GPG / PGP signatures should be more visible and whatnot, just add some visual feedback (verified? legit?, etc.), and some e-mail service providers actually do this.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#83
post #5

For me, as someone with their own mail server, these technologies mostly serve to inform me that Russian IP addresses are still trying to send email in the name of my domain for some stupid reason. It makes sense that people whose business is sending email know how to set up email correctly. I'm mostly surprised at how many legitimate sysadmins struggle with getting the basics correct. Surely those dozens of DMARC em…

> Russian IP addresses are still trying to send email in the name of my domain for some stupid reason

For what it's worth, I've started seeing cybersecurity insurers requiring riders and extra payments if you don't block Russian IPs.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#84

SPF/DKIM is really about mail server reputation. So it mostly benefits larger servers like the ones run by Google, Microsoft and Yahoo. Unfortunately, that means that attempts by those larger providers to combat spam using such reputation will naturally hurt smaller providers. So the actual effects of SPF/DKIM are on the whole negative. The root problem is that we don't actually need to keep track of email server rep…

I don't think this is correct? SPF and DKIM are about ensuring that the server actually is who it says it is, not about its reputation. In other words, when you receive an email that claims to be from Gmail, SPF and DKIM help you ensure that's where the letter actually came from, not from a server just pretending to be one of Gmail's servers.

SPF more like whether the email came from a server that's authorized to send emails on behalf of a particular domain.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#85

SPF/DKIM is really about mail server reputation. So it mostly benefits larger servers like the ones run by Google, Microsoft and Yahoo. Unfortunately, that means that attempts by those larger providers to combat spam using such reputation will naturally hurt smaller providers. So the actual effects of SPF/DKIM are on the whole negative. The root problem is that we don't actually need to keep track of email server rep…

> We need to be able to treat anonymous email differently than email from people we actually know.

The simplest solution to that would be an "only show me emails from people in my address book" filter. That would mostly echo how we treat user trust on all other platforms. Genuinely surprised this doesn't exist in most email clients (or does it and I have just overlooked it so far?)

Of course that's only a partial solution and wouldn't work for accounts where you expect unsolicited mails from people you don't know. I'd see it more as a "low-hanging fruit" solution. You could also expand the heuristic, e.g. also consider previous conversations, mailing lists, etc.

(Interestingly, the "introduce a friend" functionality would come for free: You can already send contact details as a VCard in an attachment. When receiving such a mail, some email clients will show a button to quickly add the contact to the address book.)

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#87
post #73
post #42

Earlier quoted context omitted.

>SPF/DKIM is really about mail server reputation. So it mostly benefits larger servers like the ones run by Google, Microsoft and Yahoo. Unfortunately, that means that attempts by those larger providers to combat span using such reputation will naturally hurt smaller providers. So the actual effects of SPF/DKIM are on the whole negative. That paragraph is incorrect. SPF/DKIM is not about reputation. The main purpose…

preventing impersonation is an important part on correctly attributing reputation to source domains.

Yes, but judging reputation is a different system completely.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#88
Related: there are known problems with DKIM, and there's a DKIM2 effort:

* https://datatracker.ietf.org/doc/draft-gondwana-dkim2-motiva...

* https://datatracker.ietf.org/wg/dkim/about/

* https://blog.redsift.com/email/dkim/first-look-at-dkim2-the-...

The recently-held IETF 122 had a session on it:

* https://www.youtube.com/watch?v=o-0OKfyLlBs

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#89
post #40

Earlier quoted context omitted.

> that Russian IP addresses are still trying to send email in the name of my domain for some stupid reason You can set your policy to reject, that will deter the Russians from using your domain.

I used to have my policy set to reject, but then I found out some part of an Enterprise Outlook mail filtering chain was rewriting the mail I sent before checking the DKIM signature. I can't fix stupid, especially for other parties, so I changed the policy to quarantine instead. I doubt Russian spammers will care about the difference to be honest. If they accept that their email will be delivered to spam folders, why…

Because Spam has a non-zero CTR while rejected mail CTR is exactly 0.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#90
post #33
post #15

The point of SPF/DKIM/DMARC is to bind emails to domains, so no more spoofing. It is naive to expect authentication alone can reduce spams.

Finally, a comment that understands the concepts instead of insolently ranting about how useless it is.

It feels similar to people conflating green https check marks in browsers and trustworthiness.
Post reply on HN