7 comments

  • sam_lowry_5 hours ago
    &gt; Every email carries two &quot;from&quot; addresses<p>I made a presentation about exactly the same subject many years ago, but I was not shy of separating the SMTP protocol (RFC 821 and the following ) and the email message (RFC 822 and the following).<p>It makes the link between SPF, DKIM and DMARC much clearer.<p>Anyway. The article covers just the bare minimum, and in the most obscure way.<p>For those interested in the inner workings of contemporary email delivery... I recommend the posts by Alex Shakhov on LinkedIn <a href="https:&#x2F;&#x2F;www.linkedin.com&#x2F;in&#x2F;alexshakhov&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.linkedin.com&#x2F;in&#x2F;alexshakhov&#x2F;</a> (Yes, there is still meaningful content on LinkedIn, it&#x27;s just vanishingly rare)
    • ddevnyc41 minutes ago
      I&#x27;m sure I don&#x27;t speak just for myself when I ask, can you link the presentation?
    • philosopherNoob3 hours ago
      Are those posts available without logging in? This sounds like good stuff but I can’t access it.
      • sam_lowry_2 hours ago
        I think he reposts them on his consulting page <a href="https:&#x2F;&#x2F;www.sh.consulting&#x2F;blog" rel="nofollow">https:&#x2F;&#x2F;www.sh.consulting&#x2F;blog</a> and no, I am not affiliated. Just keeping an eye on the email deliverability topic as a hoppy.
  • avian4 hours ago
    Vaguely related question: what is the go-to open DMARC check implementation these days? I mean the part that checks _received_ mail against DMARC rules. It used to be opendmarc, but it seems people have been dropping it for a while because of history of breaking changes and general lack of good stewardship [1]. Anyone using pydmarc [2]?<p>It&#x27;s hard to find good info on this since 99% of search hits are people talking about setting up DMARC from the _sender_ side.<p>[1] <a href="https:&#x2F;&#x2F;bugs.debian.org&#x2F;cgi-bin&#x2F;bugreport.cgi?bug=1014058#39" rel="nofollow">https:&#x2F;&#x2F;bugs.debian.org&#x2F;cgi-bin&#x2F;bugreport.cgi?bug=1014058#39</a><p>[2] <a href="https:&#x2F;&#x2F;pypi.org&#x2F;project&#x2F;dmarc&#x2F;" rel="nofollow">https:&#x2F;&#x2F;pypi.org&#x2F;project&#x2F;dmarc&#x2F;</a>
    • oogali3 hours ago
      I use rspamd.<p>This might be a little heavy if you’re solely looking for DMARC validation, but I use the other parts of rspamd as well for inbound email.<p><a href="https:&#x2F;&#x2F;rspamd.com&#x2F;modules&#x2F;dmarc&#x2F;" rel="nofollow">https:&#x2F;&#x2F;rspamd.com&#x2F;modules&#x2F;dmarc&#x2F;</a><p>For a library, I mainly write Go and I use <a href="https:&#x2F;&#x2F;github.com&#x2F;emersion&#x2F;go-msgauth" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;emersion&#x2F;go-msgauth</a> (formerly known as go-dkim).
      • actionfromafar2 hours ago
        Url seems to be <a href="https:&#x2F;&#x2F;docs.rspamd.com&#x2F;modules&#x2F;dmarc&#x2F;" rel="nofollow">https:&#x2F;&#x2F;docs.rspamd.com&#x2F;modules&#x2F;dmarc&#x2F;</a>
        • oogali1 hour ago
          Thanks for the correction. I guess I had a mis-paste that stripped out the leading part of the hostname... weird.
          • dylan6041 hour ago
            This just brought back bad memories of websites manipulating the clipboard when copying text. The ones that append the website attribution with full URL is a crime against humanity.
    • ksajadi50 minutes ago
      We use sendops.dev for that and the rest of reputation management on AWS.
    • 1over1373 hours ago
      Indeed opendmarc seems practically abandonware.<p>rspamd is what I use.
      • brightball2 hours ago
        That is good to know. I thought it was maintained by Valimail?
  • joladev3 hours ago
    &gt; Here is the part that trips people up.<p>It&#x27;s hard to take something seriously when it&#x27;s very clearly AI generated. It&#x27;s just a coin toss on whether the information in the article is correct.
    • johncalvinyoung36 minutes ago
      Yeah. I know what DMARC does, I run a mail server, but I thought it might be an interesting blog post nonetheless. It was very very obviously generated text, and not particularly information-dense or insightful. Gave up on reading it halfway through.
  • sylware4 hours ago
    I think DMARC is missing email address with IPv[46] literals support. As being self-hosted, without paying the DNS mob, I am still blocked to send email to gmail.com because such email addresses do throw out of whack gogol code.<p>Email addresses with IPv[46] literals are intrinsincly stronger than SPF. If in the envelope or any of the &#x27;from&#x27; headers (if my memory does not fail me, there are few more headers to scan), the IPv[46] literal does not match the actual and real IP of the SMTP server, the email is dropped, not even going into any spam folder.<p>Conspiracy mode: they know and are careful not to support that, in order to create a walled garden of internet messaging for them and their friends.
    • lxgr1 hour ago
      Arguably, missing IP literal domain support is pretty far down the list of things creating today&#x27;s actual mail delivery walled garden.
    • kube-system23 minutes ago
      It is not a conspiracy theory that it is hard to maintain reliable delivery with self-hosting email. It is primarily because email filters are in part based on trust relationships, and huge amounts of spam come (or at least, did) from relatively unknown originating servers.
    • inigyou3 hours ago
      Wasn&#x27;t this removed from the email standards?
  • ShieldScopeApp1 hour ago
    [flagged]
  • effnorwood2 hours ago
    [dead]
  • cadamsdotcom5 hours ago
    [flagged]
    • dspillett4 hours ago
      <i>&gt; it&#x27;s rude to ship your first draft</i><p>To whom this should concern:<p>Oh, do pop off.<p>Bothering to write&#x2F;edit anything yourself should be given bonus points these days, not pulled apart for minor grammar&#x2F;structural&#x2F;style issues. You&#x27;ll be telling me no to flaming split initiatives next.
    • iamacyborg4 hours ago
      You’re being polite, this stinks of Claude.