Franck Martin wrote:

> "MUAs SHOULD display to the end user, in UTF8 (and punycode), in a
> non ambiguous font, the domain used for the assertion of the DMARC
> policy, as well as the result of this assertion. A non ambiguous font
> is a font where the graphical representation of a chararcter is not
> identical to the graphical representation of another chararcter in
> the same font"     
> 
> If we know what a non ambiguous font is, then may be we could
> specifiy the font name. 

I very much would like that to be included in the DMARC spec.

And what about an additional recommendation in the spec (less than SHOULD) for 
MUAs to "green bar" the Header-From when the DMARC check passed *and* the 
domain is found to be accesible at https://_dmarc.example.com *and* found to 
have an EV SSL certificate?

So that only MUAs complying with that could be branded "DMARC-compliant" or 
"DMARC-secured"... As long as Certification Authorities managed to keep EV SSL 
certificates trustworthy, that would go a long way securing email 
communications and averting phishing scams, I think.

At any rate, MUA involvement for a successful DMARC is definitely required.

Regards,
J.Gomez

_______________________________________________
dmarc mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dmarc

Reply via email to