Live data from Hacker News

Spammers are better at SPF, DKIM, and DMARC than everyone else

toad.social

91–100 of 261 posts

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#91
post #15

The point of SPF/DKIM/DMARC is to bind emails to domains, so no more spoofing. It is naive to expect authentication alone can reduce spams.

All of these technologies are basically DOA because of how fickle they are and for lack of support across the board. Most policies are set to not to deny.

DMARC is nice though. It won't stop spam. It won't stop spoofing. But you will know that someone somewhere is spamming people using your domain name. How awesome. :)

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#92

Earlier quoted context omitted.

In most organizations there is no point in a sysadmin to spend the effort in understanding how to set it up correctly as Marketing has got more authority on email. Marketing will simply demand changes to the config that they do not understand and there is nothing you can do to stop it as they will have the CEO on their side.

> Marketing will simply demand changes to the config that they do not understand and there is nothing you can do to stop it as they will have the CEO on their side. Marketing should get their own (sub)domain for sending their missives, that way the primary corporate domain's reputation is not harmed. Unless you want to run the risk of outgoing e-mails from Finance / Accounts Receivable to be sent to other companies'…

It's amusing to see this advice in this thread contrasted with the recent Troy Hunt phishing attack thread where folks are complaining about companies like Microsoft having dozens of varying domain names.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#93

Naively I thought that one value proposition of SPF, DKIM and DMARC is that reputation shifts from based on IP to be based on domain, once you set these up correctly. So as long as you can maintain a good reputation for your domain and have SPF, DKIM and DMARC correctly set up, then you can host your SMTP server at any IP and your emails will get delivered. I wonder why it doesn't work this way.

It does work like that except nobody actually knows Google or Microsoft's algorithms to allow or deny mail delivery. It's the whole SEO thing all over again.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#94
Of course they are. It's how they make their money. The big email providers generally don't make their money from selling email services, it's a thing they offer as an in to sell the services that do generate profits. On the other hand, successfully sending an email that bypasses both technical and human barriers is spammer's business.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#95
post #3

I am just having this problem. Actually getting SPF, DKIM and DMARC right and having a domain with a 0 spam score will still land you in the spam directory. It turns out, you need to have a "reputation"? before your email gets accepted into gmail. My head was spinning as to how that reputation will be built if your email just goes straight to spam. But sure, Linkedin emails are definitively not spam and their dark-pa…

> Actually getting SPF, DKIM and DMARC right and having a domain with a 0 spam score will still land you in the spam directory.

This little bit of wisdom gets passed around all the time, but it's actually not true. You can send email from a brand new domain to Google and Microsoft and whoever just fine. What you can't do is send email from a brand new domain, and a brand new email server--or an email server on a VPS, or an email server on a residential IP. Residential IP blocks are almost completely blocked, because of unsecured devices being used to send spam, and VPS blocks have the same problem. You can get around this by using a mail relay, or building your domains reputation on a server that already has a good reputation.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#96
post #92

Earlier quoted context omitted.

> Marketing will simply demand changes to the config that they do not understand and there is nothing you can do to stop it as they will have the CEO on their side. Marketing should get their own (sub)domain for sending their missives, that way the primary corporate domain's reputation is not harmed. Unless you want to run the risk of outgoing e-mails from Finance / Accounts Receivable to be sent to other companies'…

It's amusing to see this advice in this thread contrasted with the recent Troy Hunt phishing attack thread where folks are complaining about companies like Microsoft having dozens of varying domain names.

> […] about companies like Microsoft having dozens of varying domain names.

There's a difference between one and dozens, and even between one dozen and dozens.

Most companies are not of Microsoft's size either: just having news.example.com would probably be sufficient for a lot places.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#97

SPF/DKIM is really about mail server reputation. So it mostly benefits larger servers like the ones run by Google, Microsoft and Yahoo. Unfortunately, that means that attempts by those larger providers to combat spam using such reputation will naturally hurt smaller providers. So the actual effects of SPF/DKIM are on the whole negative. The root problem is that we don't actually need to keep track of email server rep…

I don't think this is correct? SPF and DKIM are about ensuring that the server actually is who it says it is, not about its reputation. In other words, when you receive an email that claims to be from Gmail, SPF and DKIM help you ensure that's where the letter actually came from, not from a server just pretending to be one of Gmail's servers.

The foundation of reputation is reliable identity.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#98
post #5

For me, as someone with their own mail server, these technologies mostly serve to inform me that Russian IP addresses are still trying to send email in the name of my domain for some stupid reason. It makes sense that people whose business is sending email know how to set up email correctly. I'm mostly surprised at how many legitimate sysadmins struggle with getting the basics correct. Surely those dozens of DMARC em…

> Russian IP addresses are still trying to send email in the name of my domain for some stupid reason For what it's worth, I've started seeing cybersecurity insurers requiring riders and extra payments if you don't block Russian IPs.

Ive got a server hosting a number of things, amd monitoring setup for a lot of stats. Got tired of seeing blips because various countries were beating on my server, not a DoS, but enough requests to notice, and sometimes generate an alert. I blocked 7 countries, in full, and the impact was fantastic. No more 2gb of logs generated every day by countries that have no business accessing my server.

Unless you own a global business, i see no reason to even allow other countries access. The potential for attacks is too great, especially from some very specific countries.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#99

Earlier quoted context omitted.

> Russian IP addresses are still trying to send email in the name of my domain for some stupid reason For what it's worth, I've started seeing cybersecurity insurers requiring riders and extra payments if you don't block Russian IPs.

Ive got a server hosting a number of things, amd monitoring setup for a lot of stats. Got tired of seeing blips because various countries were beating on my server, not a DoS, but enough requests to notice, and sometimes generate an alert. I blocked 7 countries, in full, and the impact was fantastic. No more 2gb of logs generated every day by countries that have no business accessing my server. Unless you own a globa…

> I blocked 7 countries

Russia, China, Nigeria, Romania, North Korea, Iran and Belarus [1]?

[1] https://www.ox.ac.uk/news/2024-04-10-world-first-cybercrime-...

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#100
post #51
post #13

Earlier quoted context omitted.

Or perhaps, why do you lock the door to your house? A few solid kicks will open most doors, the locks can be picked, someone can smash windows and enter, and many modern homes can be entered by ripping the wall open with a crowbar and axe. It's to stop midrange threats.

Doors and locks are purely social construct. For majority of people it's much easier to justify stealing from a porch compared to breaking in. No more, no less. For spammers on other hand it's just a business, there will be no reprecussions like ever and we know quite a few big and legitemate companies who started their path with marketing spam sometimes using leaked email databases.

The way you're using "justify" here, makes it seem as if you think people feel it's morally legit to steal, if it's on a porch for... reasons?! From a moral perspective, theft is theft. There's no way someone can sanely claim they thought it was a free thing, because it wasn't locked away.

Doors and locks are there to make theft harder, more overt, loud, etc, and by no means validate when it's legit to be a vile thief.

Likewise, all spam is spam. The use of tools to make it more difficult for spammers to be spammers, is the same as having doors and locks. It makes it more difficult.

edit: What I said was, you clained they tried to justify it. So no worries, I was not implicating you.

Post reply on HN