Live data from Hacker News

DKIM2 and DMARCbis Have Landed

stalw.art

81–90 of 100 posts

Re: DKIM2 and DMARCbis Have Landed

#81
post #57
post #43

Earlier quoted context omitted.

Incorrect. A bounce is a delivery status notification generated by a mailer after it has already accepted a message for delivery. A 5xx permanent error is a refusal to accept the message in the first place.

Is this standarized terminology in some RFC like SMTP? Or is it presumably some well established folk lingo?

They're referring to the bounced notification message, not the fact that the mail bounced. Verb and noun.

A 5xx is a bounce, and results in a bounced email message. Variances always abound, but I'll stick with my 30 year old terminology, and it is correct.

Re: DKIM2 and DMARCbis Have Landed

#82
post #57
post #43

Earlier quoted context omitted.

Incorrect. A bounce is a delivery status notification generated by a mailer after it has already accepted a message for delivery. A 5xx permanent error is a refusal to accept the message in the first place.

Is this standarized terminology in some RFC like SMTP? Or is it presumably some well established folk lingo?

jeffbee isn't offering any explanation, maybe because it's obvious to them they don't think they need to, or something like that... so I'll volunteer one.

If you send an email, your client would talk to your local MTA (i.e. the SMTP server you own or are authorised to relay mail through, e.g. ISP). The local MTA usally just accepts the email to insert it into a queue for attempting delivery. When your MTA processes the queue, and talks to another and gets 5xx or 4xx response, your MTA will generate a "bounce" (non-delivery report) email that lands in your inbox with the details of the response it received.

So jeffbee is correct that when the local MTA gets a 5xx or 4xx response code in the SMTP session with target MTA, that /the response code is not a bounce/. Microsoft responding with 5xx or 4xx in the SMTP session, they are not bouncing the email. They are refusing to accept delivery.

For Microsoft to "bounce every email" from the original parent commenter, it would have accept each email first, and then use the return path address of each email accepted to send a bounce email asynchronously, i.e. the bounce is not part of the original session.

If a MTA talks to another MTA who accepts a message for delivery, they can then bounce the email at any later point via the address specified in the return path header. Why? Maybe incoming email is queued and scanned, because it would take too long to determine if it passes secondary rules when it's initially being accepted.

Given how this works, you could take an email inbox you received a year ago, or five... and send an email with whatever content to the return path address, and you have "bounced" the original email.

Re: DKIM2 and DMARCbis Have Landed

#83
post #51

Earlier quoted context omitted.

They keep finding that huge spam campaigns were run by one guy from his bedroom. I can't remember which specific spam campaign was recently caught, it might've been the phone spam about car insurance. It was one guy with a huge botnet. In total they are a finite set, and even catching 5% of them will scare the rest.

I interpret that the opposite way: if a huge spam campaign can be run by a guy in his bedroom, there’s no way that larger spam operators can be effectively killed by legal action. They’ll just employ different guys in different bedrooms. The same thing is true with phone phishing scams—they’re not individually hard to eradicate, but the combination of lucrativeness and rapid-rebootability means that legal crackdowns…

Did you know you can stay out of jail if you tell the police who's paying you?

Re: DKIM2 and DMARCbis Have Landed

#84
post #81
post #57

Earlier quoted context omitted.

Is this standarized terminology in some RFC like SMTP? Or is it presumably some well established folk lingo?

They're referring to the bounced notification message, not the fact that the mail bounced. Verb and noun. A 5xx is a bounce, and results in a bounced email message. Variances always abound, but I'll stick with my 30 year old terminology, and it is correct.

That's fair with regards to your statement, but "doubled112" assigned the agency to Microsoft, saying that "Microsoft bounces" their traffic, which is demonstrably not what is happening.

Re: DKIM2 and DMARCbis Have Landed

#85

Earlier quoted context omitted.

1. I can't say I buy this excuse, but okay. 2. Is this an actual problem that has arisen with a worrying frequency in the past, or just a hypothetical? And how is it different from someone stealing your SSH key or TLS certificate? 3. Isn't it obvious from previous emails you've received from the same server?

1. There are a lot of domains out there and all of the people who own them aren't necessarily technical enough to setup DKIM on their mail server. Ideally those people are using some type of service. SPF is much simpler in this regard. 2. This is a rather famous story about it happening. https://www.wired.com/2012/10/dkim-vulnerability-widespread/ I have no idea how widespread the issue is today but I had to do some…

Re: #3, shouldn't this be per-domain anyway, rather than per server? If a domain has one server signing and another one not signing then something feels wrong. It seems pretty fine to just look at what the domain did in the past as the basis, no?

Re: DKIM2 and DMARCbis Have Landed

#86

Earlier quoted context omitted.

1. There are a lot of domains out there and all of the people who own them aren't necessarily technical enough to setup DKIM on their mail server. Ideally those people are using some type of service. SPF is much simpler in this regard. 2. This is a rather famous story about it happening. https://www.wired.com/2012/10/dkim-vulnerability-widespread/ I have no idea how widespread the issue is today but I had to do some…

Re: #3, shouldn't this be per-domain anyway, rather than per server? If a domain has one server signing and another one not signing then something feels wrong. It seems pretty fine to just look at what the domain did in the past as the basis, no?

Since multiple services can send on behalf of the domain, DKIM has to be configured for each of them. A service provider, like Google, will likely use the same private key across any of their servers that is sending your mail but Sendgrid won't have access to that private key so they have to setup their own. Same goes for any other services that send mail using your domain.

As a receiving mail server, they have no way of knowing how many different parties are legitimately sending email on behalf of your domain.

SPF is per domain. You setup a DNS record at the domain (or subdomain) level that lists all of the IPs (or a DNS reference to a list of those IPs) that are authorized to send email on your behalf...but, that breaks with mail forwarding and mailing lists.

SPF is much simpler, absolutely. DKIM requires a private key to sign outgoing messages from every mail server sending mail on your behalf.

Re: DKIM2 and DMARCbis Have Landed

#87
post #74

Earlier quoted context omitted.

1&2 sound worse after this update as described.. I'm not really sure why we are still bothering with this when DNSSEC progress means DANE like setups could solve the original E2E S/MIME issues of payment and domain indicating expectation of what its email senders are required to have for S/MIME. There are some aspects of (possibly positive) deniability by an individual that probably still remain with DKIM but they ki…

What DNSSEC progress?

I don't consider 100% the goal since I'm happy if the average squatter/spammer/landing-page maker finds no value in steps to reaching more discerning clients given correlating filters. It seems likely to me that the percentage is near the tipping point where any serious organization is probably doing DNSSEC or having discussions about why they have IT problems and should be as serious now as they are for the email standards. For example, the validating DNSSEC looks higher than domains with functioning DKIM usage:

https://stats.labs.apnic.net/dnssec?s=Validating&d=01%2F06%2... https://stats.labs.apnic.net/dnssec?s=Validating&d=01%2F06%2... https://stats.labs.apnic.net/dnssec?s=Validating&d=01%2F06%2... https://stats.labs.apnic.net/dnssec?s=Validating&d=01%2F06%2...

Re: DKIM2 and DMARCbis Have Landed

#88
post #36

Earlier quoted context omitted.

It is so much easier to set these things up with a frontier AI to walk you through the Byzantine steps.

It takes an afternoon to set up DKIM and DMARC from scratch on a debian VPS. Yeah it's a little bit byzantine but it's not rocket science.

Yeah I did that. Now it seems I have to set up DKIM2 and DMARC2 and DCRAP3 and DSHIT4 for another afternoon instead of just going to work and getting shit done.

Re: DKIM2 and DMARCbis Have Landed

#89
post #74

Earlier quoted context omitted.

What DNSSEC progress?

I don't consider 100% the goal since I'm happy if the average squatter/spammer/landing-page maker finds no value in steps to reaching more discerning clients given correlating filters. It seems likely to me that the percentage is near the tipping point where any serious organization is probably doing DNSSEC or having discussions about why they have IT problems and should be as serious now as they are for the email st…

I don't think it's the case that serious orgs are generally doing DNSSEC. Rather the opposite.

https://dnssecmenot.fly.dev/

Re: DKIM2 and DMARCbis Have Landed

#90

Earlier quoted context omitted.

> Aw hell. How many things do I have to set up just so that I can send e-mails from my own domain? ... said every spammer. I'm sorry for your pain, and I'm in the same boat. But it's important to understand that any sufficiently large, distributed-agent system (like federated email), will see the rise of parasites that will pump resources and diminish the value of the system. What we're seeing here is an "immune" res…

>>parasites that will pump resources and diminish the value of the system. Countries' legal systems really need to do something about them.

I think about software engineering as virtual construction.

In the physical world, we can have police that go after criminals who break down doors. But builders also have a responsibility to install locks.

And negligently failing to build a lock is actually not a great look if you want police to give you the time of day.

Post reply on HN