On Fri, 29 Apr 2022, Tobias Fiebig via mailop wrote:

Heho,
This might be a bit of a theoretical attack thing, but looking over the bounces
for my nightly outbound DMARC reports I actually started to wonder about this;
(Mostly because I am getting scared by regularly sending DMARC reports to non
-existing accounts on a major ESP ;-)).

It's scary, and your scenario looks very real.

I regularly get bounces from Google due to DMARC reports being sent to non-existant addresses handled by Google.

I've even considered stopping sending DMARC reports entirely, as one could argue that they don't serve any positive purpose for the reporter, and may even have a negative impact, as you have described.

In an ideal world, people setting DMARC records would make sure the addresses exist and work, but hey, who am I to give advice :)

Cheers.

_______________________________________________
mailop mailing list
[email protected]
https://list.mailop.org/listinfo/mailop

Reply via email to