On Thu, Mar 28, 2013 at 5:41 PM, <[email protected]> wrote:
>Message: 6
>Date: Fri, 29 Mar 2013 00:41:25 +0100
>From: "J. Gomez" <[email protected]>
>To: <[email protected]>
>Subject: Re: [dmarc-discuss] Will DMARC make it hard for
> outsourcedmarketing mail operations?
>Message-ID: <[email protected]>
>Content-Type: text/plain; charset="iso-8859-1"
[snip]
>Consider for example this email (not spam, I subscribed to it) advertising
>some SSL certificate products from Thawte. It seems they are using a company
>named "rSys3"...
That's Responsys (where I worked for 4.5 years), one of their
non-branded domains. If Thawte wanted to, they would delegated a
subdomain such as email.thawte.com to Responsys, then use that as
their PRA domain. Then they could publish a DMARC record.
>This approach does indeed fully authenticate the sender, but it is highly
>unlikely that such a sender ("rsys3.com") would be in the recipient's (or the
>recipient's mailbox provider's) domain whitelist, so all that successful
>authentications could be moot in the end for practical purposes.
One of the main practical purposes of DKIM authentication for senders
is enrollment in Yahoo's spam complaint feedback look. Any type of
DKIM authentication suffices for that, although full alignment between
the DKIM d= domain and the PRA domain is ideal.
>Also, this approach is highly suspicious to receivers, as the advertised
>brand's domain is absent from both RFC5321.MailFrom and RFC5322.From, see for
>example this comment:
>http://proxy.org/forum/lounge/1799-email-adbrite-rsys3-com-phishing.html
Yes, this type of non-branded domain is more likely to be percieved as
phishing, which is why domain branding is recommended. Some clients
can't or won't do that.
>My guess here is that the outsourced email marketing company had such a hard
>time getting hold of someone technical...
Nope. We never had any problem getting ahold of the technical types
when I was at Responsys. We had problems w/ domain policies that
precluded delegation to others.
--
Tim Starr
Senior Deliverability Analyst
SendGrid, Inc.
_______________________________________________
dmarc-discuss mailing list
[email protected]
http://www.dmarc.org/mailman/listinfo/dmarc-discuss
NOTE: Participating in this list means you agree to the DMARC Note Well terms
(http://www.dmarc.org/note_well.html)