‹ BackHN Continuity

Thread

How to set up SPF, DKIM, and DMARC for your sending domain

92 points · 31 comments · spy888

  1. adiabatichottub · · focus · HN ↗
    I recently tried bouncing mail during the header phase when DMARC didn't align, but it rejected more legit emails than SPAM. Most of the junk we've been getting passes DMARC and has an unsubscribe link.
    1. marcus9999 · · focus · HN ↗

      [dead]

    2. thayne · · focus · HN ↗
      DMARC doesn't really do much to prevent general spam. It prevents spoofing the from address, which provides some protection against phishing, but if the email is from the domain it claims to be, it can pass DMARC whether or not it is spam.
      1. adiabatichottub · · focus · HN ↗
        Indeed. Ultimately we're still relying on blacklists, Bayesian filters, and hueristics to detect actual SPAM.
    3. edelbitter · · focus · HN ↗
      > Most of the junk we've been getting passes DMARC and has an unsubscribe link.

      You say that like its a problem.. its a formidable solution!

      Has worked for me for many years now: Just fail2ban-style block (groups of) relays that attempt to send an unsubscribe-link destined for a mailbox that never ever subscribes to anything. Those malicious-compliance folks add these unsubscribe links everywhere because they determined that its a cheap method for reducing blocks. That makes them reliably stand out whenever they hit strictly human-to-human mailboxes that simply never have any reason to "unsubscribe". Its like a honeypot, and all it took was a strict policy about what a tiny fraction of mailboxes can and cannot be used for.

      1. adiabatichottub · · focus · HN ↗
        I'll have to ponder the method you describe. I know I could implement that on my own mailboxes and some automated endpoints, but not sure how that would work for other users on our domain.
        1. edelbitter · · focus · HN ↗
          Your suitable mailboxes will be very distinguishable by grepping for past triggers per original/unexpanded recipient. Most older destinations would have thousands of non-spam hits, the suitable ones will have 0-3 with an obvious quick fix. For me it was department-level to-whom-it-may-concern aliases: All the mailing lists and web service signups use the appropriate department/employee name, yet much of the incoming mail sent by humans - and: much of the mailing-list-impostors - comes through one of the aliases that merely clarify the topic/location but end up in the same boxes anyway.
    4. 2000UltraDeluxe · · focus · HN ↗
      DMARC is for authenticating the sender, not filtering spam.

      Spammers are quite proficient at using authentication, whereas legitimate users are stuck in the 2000s wondering why their forwards don't work anymore.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.