On 12/9/20 4:04 PM, Brandon Long wrote:


When you switch to p=quarantine pct=0, no one should apply quarantine (so it's equivalent to p=none), but Groups will start rewriting, thereby removing all of those failures from your reports.  Yes, you won't see those messages in the reports at all anymore because they are no longer using your domain.

Is that what's going on with some of the messages I see on this list? That seems pretty awful from a security standpoint. Basically you're engineering a lookalike From address attack. The one big disappointment from my standpoint is that MUA's don't seem to be using auth-res, etc, to do some basic annotation. At least Thunderbird. And I don't recall gmail doing anything either.

Mike


_______________________________________________
dmarc mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dmarc

Reply via email to