Live data from Hacker News

DKIM2 and DMARCbis Have Landed

stalw.art

91–100 of 100 posts

Re: DKIM2 and DMARCbis Have Landed

#91
post #80
post #61

Earlier quoted context omitted.

> Or just use Hashcash or any other PoW. People love the idea of this, but i don't think it really makes sense. How high do you set the PoW to? I dont think there is any middle ground that would actually deter attacks but not deter legit users.

When I have personal email server and I need just ocasionally send email or two it can be as high as possible. I just want them delivered not into Spam folder.

Yeah, but you pay the cost for outgoing messages and set the cost for incoming messages. The incentives aren't super well aligned, and its difficult to convince people to pay a cost to contact you when they cant force it to be reciprocal.

The point i was trying to make though, is that we are past the era of brute forcing email addresses to send spam. Most spam is at least a little targeted.

If you are an attacker and need to send 100,000 emails a week, that means your budget you can spend on each PoW is six seconds.

This is easily parallizable and you can get budget vps's for about $5/month (i dont know if its more ecconomically efficient to get more powerful VPS or lots of cheap ones, but your mail server is probably in the range of a budget vps so i think its a fair comparison).

So some back of the napkin math, if the marketer wants to send 100,000 emails a week it costs them very very roughly $1.25 per 6 seconds of PoW.

If they have a marketing budget of $500 (which seems very small by most advertising budgets). Then you need a proof of work that takes 40 minutes per email to deter them. I dont think most email providers would find that acceptable, and i also made a bunch of simplifying assumptions here that i think lean in the direction of making PoW sound better than it is.

Re: DKIM2 and DMARCbis Have Landed

#92
post #89

Earlier quoted context omitted.

I don't consider 100% the goal since I'm happy if the average squatter/spammer/landing-page maker finds no value in steps to reaching more discerning clients given correlating filters. It seems likely to me that the percentage is near the tipping point where any serious organization is probably doing DNSSEC or having discussions about why they have IT problems and should be as serious now as they are for the email st…

I don't think it's the case that serious orgs are generally doing DNSSEC. Rather the opposite. https://dnssecmenot.fly.dev/

Sure, biggest Brand/Monopoly (and largely US) Tech is of course an interesting situation with a few different directions for interpretation. Yet, I think that many of them simply have to add DNSSEC, IPv6, etc as soon as the numbers finally look too much like 50%+, I.e. MS is about half the sites and already has selectively added it, usually where the consumer brand consequence is theirs via a SaaS product.

Re: DKIM2 and DMARCbis Have Landed

#93
post #89

Earlier quoted context omitted.

I don't think it's the case that serious orgs are generally doing DNSSEC. Rather the opposite. https://dnssecmenot.fly.dev/

Sure, biggest Brand/Monopoly (and largely US) Tech is of course an interesting situation with a few different directions for interpretation. Yet, I think that many of them simply have to add DNSSEC, IPv6, etc as soon as the numbers finally look too much like 50%+, I.e. MS is about half the sites and already has selectively added it, usually where the consumer brand consequence is theirs via a SaaS product.

As you can see, after 30+ years of effort, we are nowhere close to 50%, or even 25%, of deployment on real sites.

Re: DKIM2 and DMARCbis Have Landed

#94

Earlier quoted context omitted.

Re: #3, shouldn't this be per-domain anyway, rather than per server? If a domain has one server signing and another one not signing then something feels wrong. It seems pretty fine to just look at what the domain did in the past as the basis, no?

Since multiple services can send on behalf of the domain, DKIM has to be configured for each of them. A service provider, like Google, will likely use the same private key across any of their servers that is sending your mail but Sendgrid won't have access to that private key so they have to setup their own. Same goes for any other services that send mail using your domain. As a receiving mail server, they have no wa…

> A service provider, like Google, will likely use the same private key across any of their servers that is sending your mail but Sendgrid won't have access to that private key so they have to setup their own. Same goes for any other services that send mail using your domain.

I'm sorry, I'm so lost and confused. Why would a service like SendGrid be impersonating a random domain without being able to get a private key from the domain owner? Like you're saying SendGrid offers the ability to send emails from a domain like @gmail.com without its private key?

Re: DKIM2 and DMARCbis Have Landed

#95
post #88

Earlier quoted context omitted.

It takes an afternoon to set up DKIM and DMARC from scratch on a debian VPS. Yeah it's a little bit byzantine but it's not rocket science.

Yeah I did that. Now it seems I have to set up DKIM2 and DMARC2 and DCRAP3 and DSHIT4 for another afternoon instead of just going to work and getting shit done.

Good heavens an entire other afternoon after a decadal standards update. You’ll have to spend an afternoon upgrading off XP at some point too.

Re: DKIM2 and DMARCbis Have Landed

#96
post #93

Earlier quoted context omitted.

Sure, biggest Brand/Monopoly (and largely US) Tech is of course an interesting situation with a few different directions for interpretation. Yet, I think that many of them simply have to add DNSSEC, IPv6, etc as soon as the numbers finally look too much like 50%+, I.e. MS is about half the sites and already has selectively added it, usually where the consumer brand consequence is theirs via a SaaS product.

As you can see, after 30+ years of effort, we are nowhere close to 50%, or even 25%, of deployment on real sites.

Secure shell had to wait quite a while for gradual adoption by anyone new and caskets of the older to pile up. SSL wasn't exactly shiny new in 2014 when LetsEncrypt was brought in to make it prevalent together with Google pressure. Similar pressure has the same groups picking DNSSEC experience up just in the last year.

If we put aside the advertising for a moment, the US had the same problems with every technology that is newer than landlines. Big investments in companies that will be prevented from failing will try to keep the US behind the trend but a few US companies will see that they better get ahead of where the rest of the world is going with or without US tech.

Re: DKIM2 and DMARCbis Have Landed

#97
post #93

Earlier quoted context omitted.

As you can see, after 30+ years of effort, we are nowhere close to 50%, or even 25%, of deployment on real sites.

Secure shell had to wait quite a while for gradual adoption by anyone new and caskets of the older to pile up. SSL wasn't exactly shiny new in 2014 when LetsEncrypt was brought in to make it prevalent together with Google pressure. Similar pressure has the same groups picking DNSSEC experience up just in the last year. If we put aside the advertising for a moment, the US had the same problems with every technology th…

No, it didn't. SSH adoption was nearly universal with a year or two of its release. TLS was nearly universal on commercial sites long, long before LetsEncrypt. SSH and TLS are not comparable in adoption to DNSSEC.

Re: DKIM2 and DMARCbis Have Landed

#98
post #84
post #81

Earlier quoted context omitted.

They're referring to the bounced notification message, not the fact that the mail bounced. Verb and noun. A 5xx is a bounce, and results in a bounced email message. Variances always abound, but I'll stick with my 30 year old terminology, and it is correct.

That's fair with regards to your statement, but "doubled112" assigned the agency to Microsoft, saying that "Microsoft bounces" their traffic, which is demonstrably not what is happening.

It is what's happening, as I've described. A 5xx is a bounce.

You don't agree with my terminology, but we're not disagreeing on what's happening. In this case, as per my dictionary, 'rejected' and 'bounced' are synonyms. If this was me, and my MTA hitting this Microsoft server, my MTA/server would see the bounce(5xx), then my MTA/server would generate a bounce message(email) which I'd receive in my inbox.

The bounce message is a result of the bounce. The action/cause is the bounce/reject 5xx.

How can you have a bounce message, without a bounce happening?

Again, you don't agree with this terminology, and that's fine. But I'm not pulling this out of a random hat, it's 30+ year old terminology that I've used with endless people locally and online. That doesn't mean your view is wrong, we may just be running into local variances in lingo.

There are all sorts of edge cases in our compute discourse. I ran into a company where they didn't use initialisms to discuss daemons/protocols, but treated them as acronyms. Of course, they didn't really discuss such things often. So when discussing smtp, they'd pronounce it 'sim-tee'. Of course, sntpd, smtpd, snmpd, and others are all pronunced 'sim-tee', which makes for a fun meeting. Think of it as 'I am groot' taken too far. For prudence, I kept enforcing initialisms, which of course resolved this.

Anyhow! Point is, well.. not really sure except info.

Re: DKIM2 and DMARCbis Have Landed

#99

Earlier quoted context omitted.

Since multiple services can send on behalf of the domain, DKIM has to be configured for each of them. A service provider, like Google, will likely use the same private key across any of their servers that is sending your mail but Sendgrid won't have access to that private key so they have to setup their own. Same goes for any other services that send mail using your domain. As a receiving mail server, they have no wa…

> A service provider, like Google, will likely use the same private key across any of their servers that is sending your mail but Sendgrid won't have access to that private key so they have to setup their own. Same goes for any other services that send mail using your domain. I'm sorry, I'm so lost and confused. Why would a service like SendGrid be impersonating a random domain without being able to get a private key…

I'll try to explain.

Say I decide to open a pirate themed gym called Slimmer Ye Timbers and buy the domain slimmeryetimbers.com.

If I want to setup a website, I will go to a hosting company, set something up, go into the DNS and point a couple of records for the top level domain and the www subdomain to the hosting company.

If I want to receive email sent to argh@slimmeryetimbers.com I need to setup a mail server (Google, Outlook, web host may offer one, could setup an open source one, etc) and once it's setup I go to the DNS to point an MX record at the mail server.

So far, if people try to lookup my website or send an email TO me everything is pretty straightforward.

Now, if I want to send email that says it's FROM argh@slimmeryetimers.com is where things get weird. Because I don't have to do anything.

Any server, anywhere can just do it and every mail server that receives a message saying it's from that domain has to try to figure out if it really is or isn't. This is where antispam rules come in. Without DMARC, SPF & DKIM in place receiving mail servers will build up trust in different IP addresses, typically from vendors who go out of their way to prevent email abuse specifically to protect the reputation of those IP addresses. The receiving mail server my do a reverse DNS lookup to see if the hostname matched. They might see if the MX server used by domain is the same server sending the message along with a ton of other algorithmic hoops to make a good judgement. Even with DMARC, SPF and DKIM in place they may still use those rules.

DMARC, when strictly enforced with p=reject, let's you signal the receiving mail server that all mail claiming to be from your domain can be validated and if it can't be validated that message isn't from you and can be discarded. All that DMARC does is say that if you receive a message from this domain, it should pass either SPF OR DKIM for this domain as well.

So let's say, for example that I'm using both Google Workspace and Sendgrid for email for slimmeryetimbers.com. I'll setup Gmail for my main professional email for myself and my staff and I'll setup Sendgrid to send email from the website (responses to contact forms, etc).

For SPF it can be pretty simple, a single TXT record:

"v=spf1 include:_spf.google.com include:sendgrid.net ~all"

Both Google and Sendgrid publish DNS records with the IP address of their servers and keep them up to date, so adding that include is all that we have to do.

DKIM is more complicated. Google will provide you with a DKIM record to put under a subdomain that includes the public DKIM key. Once they have verified it's setup, they will sign every email sent from your account with the private key that only they know. When a receiving server gets the message they will see that the message has been signed by DKIM and it will point to the subdomain where the public key was stored. By following the instructions from the signature in the email and using the public key, they can verify that the message was actually signed by the private key and hasn't been tampered with.

If we then setup Sendgrid they will give you their own DNS records for DKIM that work for their own private key. In both of these situations, we never get our hands on the private key because we are using a 3rd party service that doesn't disclose it. Sendgrid issues 2 CNAME records that point to DKIM public key records on their DNS so that they can control them. They'll send out messages signed with one private key and then later switch to a different private key while the original key and it's public record is changed, transparently without you having to deal with it.

If we were to setup our own mail servers, we would have access to it though. It's also entirely possible for somebody with access at an email company to go steal the private keys of their customers and sell them, or just use them. It's possible for those services or our mail servers to be hacked/compromised and the keys be stolen. Built in rotation process helps with this. It's the same reason that Let's Encrypt issues secure certificates that expire after 90 days (sometimes less). Just key rotation.

That was long but I hope it helps?

Re: DKIM2 and DMARCbis Have Landed

#100
post #58

Earlier quoted context omitted.

DMARC isn't for sending email successfully, it's for preventing other people from impersonating your domain. Without it, there's nothing stopping anybody from sending an email saying it is from you@qurren.com. SPF tried. DKIM tried. Both of them had gaps. When you use them together and have a DMARC policy that requires one of them or the other for successful delivery, it's the best current solution.

Right, and when you don't configure DMARC successfully and the recipient requires DMARC, then you cannot send email successfully.

That's a feature, not a problem.
Post reply on HN