On Apr 15, 2023, at 7:52 AM, Hector Santos <[email protected]> wrote:
Hector, respecfully, I disagree with several of your points. * You seemes to be saying that when spf fails then usually dkim fails, too. I’ve seen first hand that’s nit true. * you seemed to be placing too much weight on the value of spf hardfail. Even 10 years ago, few receivers rejected on an spf hardfail. Some do but it’s not at all reliable. DMARC is accepted by most as the new policy layer. It’s where policy should be handled. The OR logic is in part to get away from the policy layer that breaks fairly easily (e.g., forwarding). SPF is important but given a choice between authenticating with just aligned SPF or just aligned DKIM, I’d choose DKIM. Could you provide a citation for the following claim: “Over 88% of the time, when SPF fails, DKIM/ADSP/DMARC, if available would also fail. So the payoff is high to short-circuit and lowered when you needless transfer a potential large and harmful payload.” I’m skeptical and I’d imagine some others are too so a cite would go a long way. Thanks. Neil |
_______________________________________________ dmarc mailing list [email protected] https://www.ietf.org/mailman/listinfo/dmarc
