I figured out how DMARC works, and it almost broke me
simonandrews.ca
simonandrews.ca
* SPF: Tell the world which servers are allowed to send email for your domain
* DKIM: Weak version of digitally signed email, add a header that only mailservers that have the private key you supply can generate. Tampering invalidates the signature (for example when an email gets relayed for a second time). The private key used counts for your whole domain.
* DMARC: Tells other mailservers what to do when the SPF and/or DKIM check fails, and also allows you to set an address where to send reports to. These reports contain counts of messages that failed the SPF and/or DKIM checks.
SPF is about the domain in the envelope address.
DKIM signatures can reference any DKIM selector on any domain.
But DMARC also checks that the domains used match the domain of the From header. DMARC passes when at least one of the two is aligned. It’s possible to require strict alignment (exact domain) or allow subdomains as well.
SPF, DKIM, DMARC are even more useless than the dbl protocol of spamhaus.
Also: this DMARC action is used for tracking whether or not an email was received, without the client of the receiving address needing to do any action.
So yep, it's also a privacy invasion.
Isn't it just the receiving mail SERVER acknowledging receiving the message? That says nothing about mailbox access or reading. I would not consider it a privacy invasion.
Most modern communication apps have a similar process of separating "sent", "received" and "displayed to user" which is super useful. Apart from the last part I would not consider them a privacy violation and you can usually turn that off. Similarly, if I download my mail to a local client, the server never knows if or when I read it and definitely not the sender.
But maybe I am missing your point, could you elaborate if that is the case?
It does help stop false attribution of spam mail, though; spammer@example.net can't pretend to be sending mail from example.org.
It does lose its effectiveness when huge mail domains (e.g. GMail) can pump out so much spam, though, or when domains share email hosts (and therefore different tenants will be sending from the same IP addresses - another reason why IPv4 exhaustion is bad, isolation would work better with IPv6).
It's only "and" in this statement. You can't use DMARC to tell mailservers what to do when only one of them fails, as DMARC passes if at least one passes. The report will say which ones pass or not though.
- Cloudflare Email Routing and DMARC Management. If all you need is inbound email inboxes at a custom domain that routes to your GMail or other addresses, this is the way to go.
- Fastmail. If you want an alternative to GWorkspace that is cheaper and more lightweight and that has its own non-Google mobile apps and a fast web app. Also if you need IMAP, POP, SMTP support.
- GWorkspace. Sometimes you just have to give in to the overlords. If you need inbound/outbound business mail that just works and integrates with all the Googley services, including GMail and GDrive, you just have to give in to this. Cloudflare makes the DNS setup easier if you go with this option. (They have a x-admin-panel integration.)
- Honorable mention for Opalstack.com. They'll give you open source powered email-server-in-a-box. On a shared Linux server, Procmail rule support, and with Roundcube access for mailboxes.
- The tool https://learndmarc.com is particularly helpful for debugging. It generates a unique email address you can send an email to and it'll tell you what's happening from an SPF, DKIM, and DMARC standpoint. All in the browser.
https://community.cloudflare.com/t/email-forwarded-through-c...
That is to say, I just picked a lenient DMARC policy and started collecting reports.
I've been collecting reports ever since, because I'm not sure why I should care.
I mostly don't get spam emails, and I mostly don't have legit emails marked as spam.
(I might have had two false positives and two false negatives in the last two years.)
I don't have a system for going through those XML DMARC blobs I get sent.
So they just get their own inbox folder that I never look at.
So...
I almost figured out how DMARC works, and I don't careIn other words, it's useful for spotting legitimate stuff that's accidentally failing, not for doing anything with the unauthorized stuff.
For a personal domain that only one or two people use, this is less likely to be worth bothering with.
But you're spot on with finding gaps. It's basically the premise for every commercial DMARC product on the market. It's also crazy to see how companies blindly trust and never remediate senders from having access to corporate domains.
I'll, however, disagree with regard to personal domains. It's not hard. Do it. Everyone who helps clean up these things makes a small difference. If you own your own domain and are leveraging email this should be table stakes. I have recommended MailHardener [0] (no affiliation) in the past for their fantastic documentation around SPF, DKIM, DMARC, BIMI, etc - but also they have a free tier of one domain and they provide a grade with respect to your posture. It's really simple, and people I know have used it to learn how to implement these configurations on a broader scale.
It still tells you how many occurrences are trying to impersonate you.
My DMARC policy is lenient, so it only ever creates reports that I don't read, it never filters.
False positive: A legit email ends up in my spam folder.
False negative: A spam email ends up in my inbox.
I check my spam folder occasionally, so that's how I count false positives.
As far as I understand from this thread, maintaining a DMARC policy set makes more sense for bigger companies that have a lot of automated email traffic and a lot of consistently shaped traffic between larger groups. My Microsoft email at work is full of useless notifications because we don't have policies set up that whitelist our main customers or even our own automated tools. ("You don't often get emails from Jira!" -- if only.)
My only beef is with this:
> If you're running a large domain, you'll get a bunch of these reports. If you're running a small one, you might be able to handle it yourself.
Even with a "small" domain, you're looking at basically another part time job to analyze these reports. It's not fun, and you grow tired of it very quickly. Sure if you're running 1 website, and that's all you do it might make sense. But for a web firm like mine (serving small biz), there's no way I can set this up for clients without charging them an extra fee and most aren't willing to pay me to spend several hours each week analyzing DMARC reports.
The secondary problem is getting my clients to care enough to open their wallets!
The only client (out of hundreds over 2+ decades) I've had with a major spoofing problem simply didn't have the budget.
If your email stops going through, you’ll hear about it before you ever get a DMARC report about it.
And yes, it feels like another cash grab.
https://workspaceupdates.googleblog.com/2023/05/expanding-gm...
The money wasn't of consequence for my organization, but we had just sunset our final remaining Digicert certificate and are fully on automatic renewing AWS ACM and LetsEncrypt certificates. It felt like a step back to have to manage a new one manually.
v=DMARC1; p=none; fo=1; rua=mailto:dmarc_agg@whatever.com;ruf=mailto:dmarc_forensic@whatever.com;pct=100
and thats it I think
I recently had to implement DKIM for my app. I finally figured it out, but I had a similar experience to the author.
I have properly and correctly implement SPF, DKIM and DMARC for years. Still, at any time Google, Microsoft or some Big Party might find - for reasons unclear - my server not trustworthy and decide to bin any mail it receives from me. Without informing the sender.
I have given up.
I've been running my own mailserver since 1999.
I've had SPF for a while but DKIM and DMARC only since last year. Had no issues sending to the big players.