ietf
[Top] [All Lists]

Re: DMARC: perspectives from a listadmin of large open-source lists

2014-04-08 10:52:32
On Tue, Apr 08, 2014 at 06:06:27AM +0100, Sabahattin Gucukoglu wrote:
On 8 Apr 2014, at 05:21, John R Levine <johnl(_at_)taugh(_dot_)com> wrote:
Mailing list apps can't "implement DMARC" other than by getting rid
of every feature that makes lists more functional than simple
forwarders. Given that we haven't done so for any of the previous
FUSSPs that didn't contemplate mailing lists, because those features
are useful to our users, it seems unlikely we'll do so now.
Well,  Mailman 2.1.16 has the FROM_IS_LIST feature that "Fixes" the
problem by putting the list address in the From: field.  That seems to
work, except that you lose information (the sender's address) if the
list wants to operate a policy of "Reply goes to list".  You can then
assure that DKIM signatures are valid and set up SPF, etc.  This also
has the effect of letting you operate through the various cloud email
platforms that try to validate sender addresses.
This breaks the ability to reply directly to the sender when the
response should NOT be on the list, as well as the ability to put a
sender in a personal killfile.

And don't start on suggesting Reply-To instead, RFC 2822 already
noted that it should be set by the author, not the list software [1].

[1] http://marc.merlins.org/netrants/listreplyto.html List Reply-To
considered harmful.

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Infrastructure Lead
E-Mail     : robbat2(_at_)gentoo(_dot_)org
GnuPG FP   : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85