[email protected] writes:

 > Forgot to mention" DKIM
 > 
 > The trifecta you must adhere to are DMARC, DKIM, and SPF.

Putting them together as if they're the same is inaccurate.  You must
provide DNS records to support DKIM and SPF for your host, and
DKIM-sign outgoing email.  DKIM signing applies to all outgoing mail,
so should be done in the MTA.   So far so good.

But the treatment of DMARC is different in kind.  It has nothing to do
with your site conforming to the DMARC protocol or providing DMARC DNS
records.  Rather, it is self-defense against side effects of others'
conformance.  Furthermore, DMARC mitigation is, and should be,
provided by Mailman.  The MTA doesn't know enough about when to do it.

Steve

-- 
GNU Mailman consultant (installation, migration, customization)
Sirius Open Source    https://www.siriusopensource.com/
Software systems consulting in Europe, North America, and Japan
------------------------------------------------------
Mailman-Users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3/lists/mailman-users.python.org/
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: https://www.mail-archive.com/[email protected]/
    https://mail.python.org/archives/list/[email protected]/
Member address: [email protected]

Reply via email to