I run an email forwarder which presents the same kinds of problems with
DMARC as mailing lists; the sender's from address will never SPF-align.
What we do is check the From header domain's DMARC policy, if  not 'none',
we rewrite the From header eg

From: [email protected]

and add a Reply-To header with the original From (actually a mangled
address that lets the reply pass back through our servers, which is done
regardless of the From rewrite and which always breaks DKIM signatures that
include Reply-To).

Rewriting the From header has raised the ire of a minority of users who
simply can't understand why we insist on messing with the From address.
'Because otherwise you might not get the mail at all' does not seem to
satisfy them, much less telling them we are respecting the senders policies
...


On Mon, Apr 7, 2014 at 5:36 PM, John R Levine <[email protected]> wrote:

> It occurred to me that I could add some custom code to my signing script
> that's called on every list message, so per Al's suggestion, I've now
> adjusted things so any message with a yahoo.com address on the From: line
> is rewritten to From: "Address redacted" :;
>
> That seems like the minimum I can do to mitigate the damage.  If Yahoo
> users find that inconvenient, well, they have options.
>
> R's,
> John
> _______________________________________________
> dmarc-discuss mailing list
> [email protected]
> http://www.dmarc.org/mailman/listinfo/dmarc-discuss
>
> NOTE: Participating in this list means you agree to the DMARC Note Well
> terms (http://www.dmarc.org/note_well.html)
>
_______________________________________________
dmarc-discuss mailing list
[email protected]
http://www.dmarc.org/mailman/listinfo/dmarc-discuss

NOTE: Participating in this list means you agree to the DMARC Note Well terms 
(http://www.dmarc.org/note_well.html)

Reply via email to