Re: [mailop] DMARC processing

2023-12-19 Thread Jesse Thompson via mailop
On Tue, Dec 19, 2023, at 7:20 PM, Tara Natanson via mailop wrote: > On Tue, Dec 19, 2023 at 3:29 PM Eduardo Diaz Comellas via mailop > wrote: >> Hi all, >> >> Thanks all for the suggestions. I will give a try to some of them to >> see if they are a good fit for our usage case. >> >> We

Re: [mailop] DMARC processing

2023-12-19 Thread Tara Natanson via mailop
On Tue, Dec 19, 2023 at 3:29 PM Eduardo Diaz Comellas via mailop < mailop@mailop.org> wrote: > Hi all, > > Thanks all for the suggestions. I will give a try to some of them to > see if they are a good fit for our usage case. > > We handle around 300 domains, most of them with 5-10 mailboxes...

Re: [mailop] Microsoft rejecting their own headers

2023-12-19 Thread Randolf Richardson, Postmaster via mailop
I wouldn't want to see their breakfast! ;) > Maybe they have just started eating their own dog food V2.0 at MS? ;-> > > SCNR. > > Best, > > -C. > > > Am 15.12.2023 um 11:37 schrieb Laurent S. via mailop : > > > > It seems Microsoft made very recently a change. Since then, we get a >

Re: [mailop] ECDSA DKIM validation?

2023-12-19 Thread Gellner, Oliver via mailop
> On 19.12.2023 at 12:19 Alessandro Vesely via mailop wrote: > > On Tue 19/Dec/2023 09:21:55 +0100 Taavi Eomäe wrote: >> Considering how Gmail and quite a few widespread DKIM implementations still >> don't support EdDSA DKIM, I wouldn't get my hopes too high. > > > Won't any Google insider

Re: [mailop] DMARC processing

2023-12-19 Thread Eduardo Diaz Comellas via mailop
Hi all, Thanks all for the suggestions.  I will give a try to some of them to see if they are a good fit for our usage case. We handle around 300 domains, most of them with 5-10 mailboxes... so the volume of reports can get pretty wild. Best regards. El 19/12/23 a las 18:16, Slavko via

Re: [mailop] SMTP smuggling

2023-12-19 Thread Marco Moock via mailop
Am 19.12.2023 um 17:20:20 Uhr schrieb Slavko via mailop: > Please, understand i properly, that it is no vulnerabiliy in SMTP > itself, but in (some) implementations/servers only? According to the stuff I read, sendmail and Postfix (and more) are affected, for sendmail a patched version exists

Re: [mailop] SMTP smuggling

2023-12-19 Thread ml+mailop--- via mailop
On Tue, Dec 19, 2023, Slavko via mailop wrote: > Please, understand i properly, that it is no vulnerabiliy in SMTP itself, > but in (some) implementations/servers only? The RFC is very precise about line endings and "end of message". Some (legacy) MTAs try to be "nice" and accept other line

Re: [mailop] SMTP smuggling

2023-12-19 Thread Slavko via mailop
Dňa 19. decembra 2023 12:31:11 UTC používateľ Mark Alley via mailop napísal: >Hey all, recently saw this mail server SMTP vulnerability that popped up on >a blog yesterday. Sharing here for those interested. Please, understand i properly, that it is no vulnerabiliy in SMTP itself, but in (some)

Re: [mailop] DMARC processing

2023-12-19 Thread Slavko via mailop
Dňa 19. decembra 2023 15:29:43 UTC používateľ Mark Alley via mailop napísal: >Is that on Github somewhere? I'd be glad to add it to the list. Thanks, but no, it is not published (officially). But if someone (small/personal/family domains) is interested, i can share it. regards -- Slavko

Re: [mailop] DMARC processing

2023-12-19 Thread Bernardo Reino via mailop
On Tue, 19 Dec 2023, Eduardo Diaz Comellas via mailop wrote: I'm starting to deploy DMARC records in all our managed domains, but we don't have any specific tool to parse and extract meaningful information from the reports. Do you have any recomendations? I process such reports using a

Re: [mailop] DMARC processing

2023-12-19 Thread Mark Alley via mailop
Is that on Github somewhere? I'd be glad to add it to the list. On 12/19/2023 9:20 AM, Slavko via mailop wrote: Dňa 19. decembra 2023 15:02:15 UTC používateľ Mark Alley via mailop napísal: https://dmarcvendors.com/#Self-Hosted_Solutions I use own python script (piped from exim), which

Re: [mailop] DMARC processing

2023-12-19 Thread Alexandre Schmit-Baverel via mailop
Here at Sarbacane, we use https://github.com/domainaware/parsedmarc to parse it in Json, then feed it to an ELK (elastic / Kibana) with a dashboard we built. Its basic but convenient as an ESP when you want to control all these data. [image: Alexandre Schmit-Baverel] *Alexandre Schmit-Baverel*

Re: [mailop] DMARC processing

2023-12-19 Thread Slavko via mailop
Dňa 19. decembra 2023 15:02:15 UTC používateľ Mark Alley via mailop napísal: >https://dmarcvendors.com/#Self-Hosted_Solutions I use own python script (piped from exim), which extracts report's attachment, stores XML in directories (by month) and reports are shown/parsed by nginx and its

Re: [mailop] DMARC processing

2023-12-19 Thread Peter E. Fry via mailop
On Tuesday 19/12/2023 at 3:12 am, Eduardo Diaz Comellas via mailop wrote: Hi, I'm starting to deploy DMARC records in all our managed domains, but we don't have any specific tool to parse and extract meaningful information from the reports. Do you have any recomendations? Most (all?)

Re: [mailop] DMARC processing

2023-12-19 Thread Mark Alley via mailop
https://dmarcvendors.com/#Self-Hosted_Solutions - Mark Alley On 12/19/2023 2:47 AM, Eduardo Diaz Comellas via mailop wrote: Hi, I'm starting to deploy DMARC records in all our managed domains, but we don't have any specific tool to parse and extract meaningful information from the reports.

Re: [mailop] DMARC processing

2023-12-19 Thread Opti Pub via mailop
https://github.com/domainaware/parsedmarc On Tue, Dec 19, 2023 at 9:50 AM Scott Mutter via mailop wrote: > If DMARC reports could be sent in JSON format, they would be more easily > parseable. > > At least, that's my opinion. > > On Tue, Dec 19, 2023 at 2:47 AM Eduardo Diaz Comellas via mailop

Re: [mailop] DMARC processing

2023-12-19 Thread Scott Mutter via mailop
If DMARC reports could be sent in JSON format, they would be more easily parseable. At least, that's my opinion. On Tue, Dec 19, 2023 at 2:47 AM Eduardo Diaz Comellas via mailop < mailop@mailop.org> wrote: > Hi, > > I'm starting to deploy DMARC records in all our managed domains, but we > don't

Re: [mailop] o365 outbound senders.. Strange Failures sending .. widespread reports

2023-12-19 Thread Bill Cole via mailop
On 2023-12-19 at 01:12:56 UTC-0500 (Tue, 19 Dec 2023 07:12:56 +0100) Benny Pedersen via mailop is rumored to have said: EHLO after STARTTLS, clearly bots only Nope. Vide: Dec 19 08:31:47 shiny postfix/smtpd[94038]: disconnect from mxout1-he-de.apache.org[95.216.194.37] ehlo=2 starttls=1

[mailop] SMTP smuggling

2023-12-19 Thread Mark Alley via mailop
Hey all, recently saw this mail server SMTP vulnerability that popped up on a blog yesterday. Sharing here for those interested. https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/ -Mark Alley ___ mailop mailing list

Re: [mailop] ECDSA DKIM validation?

2023-12-19 Thread Slavko via mailop
Dňa 19. decembra 2023 11:11:28 UTC používateľ Alessandro Vesely via mailop napísal: >Won't any Google insider shred some lite on why a generally technically sound >company lags like that? Especially, when they de facto require DKIM ... regards -- Slavko https://www.slavino.sk/

Re: [mailop] ECDSA DKIM validation?

2023-12-19 Thread Alessandro Vesely via mailop
On Tue 19/Dec/2023 09:21:55 +0100 Taavi Eomäe wrote: Considering how Gmail and quite a few widespread DKIM implementations still don't support EdDSA DKIM, I wouldn't get my hopes too high. Won't any Google insider shred some lite on why a generally technically sound company lags like that?

Re: [mailop] DMARC processing

2023-12-19 Thread Alessandro Vesely via mailop
On Tue 19/Dec/2023 09:47:15 +0100 Eduardo Diaz Comellas via mailop wrote: I'm starting to deploy DMARC records in all our managed domains, but we don't have any specific tool to parse and extract meaningful information from the reports. Do you have any recomendations? The most basic

Re: [mailop] ECDSA DKIM validation?

2023-12-19 Thread Bastian Blank via mailop
On Tue, Dec 19, 2023 at 10:21:55AM +0200, Taavi Eomäe via mailop wrote: > Considering how Gmail and quite a few widespread DKIM implementations still > don't support EdDSA DKIM, I wouldn't get my hopes too high. Please note that ECDSA != EdDSA. And EdDSA stuff only turned up in FIPS a short

Re: [mailop] ECDSA DKIM validation?

2023-12-19 Thread Marc Bradshaw via mailop
It's getting better, but RSA will be with us for some years yet. On Tue, 19 Dec 2023, at 7:03 AM, Michael W. Lucas via mailop wrote: > Hi, > > Last I checked a few years ago, validation of ECDSA DKIM keys was > still iffy on deployed servers. Has the situation improved? Can we > recommend ECDSA

[mailop] DMARC processing

2023-12-19 Thread Eduardo Diaz Comellas via mailop
Hi, I'm starting to deploy DMARC records in all our managed domains, but we don't have any specific tool to parse and extract meaningful information from the reports. Do you have any recomendations? Best regards -- Eduardo Díaz Comellas Ultreia Comunicaciones, S.L.

Re: [mailop] ECDSA DKIM validation?

2023-12-19 Thread Taavi Eomäe via mailop
Considering how Gmail and quite a few widespread DKIM implementations still don't support EdDSA DKIM, I wouldn't get my hopes too high. smime.p7s Description: S/MIME Cryptographic Signature ___ mailop mailing list mailop@mailop.org