On Sun 28/Sep/2025 07:34:52 +0200 Steven M Jones wrote:
Next up for a final review is section 7.


Wasn't Murray's replacement a review in itself.


7. Privacy Considerations The generation and transmission of DMARC failure reports (sometimes referred to as "forensic reports") raise significant privacy concerns that must be carefully considered before deployment.

There are just a few of word changes and different RFCs cited in this section under revision -16. Anybody wish to raise any concerns?


I think Steve refers to this sentence:

    These reports may expose sender and recipient identifiers (e.g.
    RFC5322.From addresses), and although the [RFC5965] format used for
    failed-message reporting supports redaction ([RFC6590]), failed-message
    reporting is capable of exposing the entire message to the Report Consumer.

The original[*] was:

    These reports may expose sender and recipient identifiers (e.g.
    RFC5322.From addresses), and although the [RFC6591] format used for
    failed-message reporting supports redaction, failed-message
    reporting is capable of exposing the entire message to the Report Consumer.

Best
Ale
--

[*] https://mailarchive.ietf.org/arch/msg/dmarc/pT79lttiFnHQlQKCZaoJ18xan8g





_______________________________________________
dmarc mailing list -- dmarc@ietf.org
To unsubscribe send an email to dmarc-le...@ietf.org

Reply via email to