Re: [mailop] ARC and not ARC, was Microsoft Announces Tenant Trusted ARC Seal

2022-06-29 Thread John Levine via mailop
It appears that Vsevolod Stakhov via mailop  said:
>> I agree that would've been better than ARC.  However, it'd still need to 
>> know which recipients are mailing list supporting DKIMv2 and operate 
>> accordingly. ...

Not necessarily. On a small system you could put fowarding signatures
on all the mail you send and hope, probably correctly, that the people
to whom your users send mail are unlikely to do malicious things with
it.

>If we ignore unknown tags safely then this extension can be introduced 
>without any additional issues with the compatibility I suppose.

If your DKIM verifier doesn't ignore unknown tags, it's not going to
work.  People add random tags all the time.  I presume you noticed that
my draft changed the v= tag so that signatures that depend on forwarding
a v=1,tag that is unknown to verifiers that don't implement the draft so
they'll consider the signature invalid.

R's,
John
___
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop


Re: [mailop] Looking for contact at iphmx.com

2022-06-29 Thread John Levine via mailop
It appears that Lena--- via mailop  said:
>> The good folks at SecurityTrails figured out a few months ago that the
>> presence of the RoundCube webmail product counts as "phishing against
>> the generic brand of email" (I shit you not)
>
>By default RoundCube doesn't include originating-IP into headers
>of outgoing emails. Default means vast majority of installations.

Neither does Gmail. What does that have to do with whether you'd want
to accept the mail?

R's
John


___
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop


Re: [mailop] Looking for contact at iphmx.com

2022-06-29 Thread Lena--- via mailop
> The good folks at SecurityTrails figured out a few months ago that the
> presence of the RoundCube webmail product counts as "phishing against
> the generic brand of email" (I shit you not)

By default RoundCube doesn't include originating-IP into headers
of outgoing emails. Default means vast majority of installations.
___
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop