ietf
[Top] [All Lists]

Re: WG Review: Domain-based Message Authentication, Reporting & Conformance (dmarc)

2014-07-15 10:45:11
Some MUAs already expose "Sender != From" by displaying
"From <sender> on behalf of <author>".  This needs to become standard
MUA behaviour.

Perhaps not.  This is the "punt security policy to Grandma" model.  A
more extreme version is the proposal to show signed and unsigned parts
of messages in different colors.

It would have been nice if users and MUAs had done this all along and
there were widely understood conventions (as opposed to well
documented but not well understood) conventions for using Sender:
headers.  But there aren't.  The most popular MUA that shows the
sender is Outlook, and people I know just find it confusing.

You and I probably have the background to make useful decisions from
various combinations of sender and author.  But I don't see any reason
to believe that non-technical users (in my case, Grandma is my wife's
74 year old mother) do.

R's,
John

<Prev in Thread] Current Thread [Next in Thread>