Re: DMARC and ietf.org

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, Aug 13, 2016 at 11:10:59AM -0400, John R Levine wrote:
> DMARC was fine when it was used to protect high value company domains like
> paypal.com.  It became much less fine when AOL and Yahoo started using it to
> force the costs of their own security failures on third parties.

Worth noting is that their deployment of DMARC has done *nothing*
to address those security failures and thus *nothing* to stop the
forgeries that were the alleged impetus for the deployment.  In fact,
it's arguably made the impact of those worse because they now arrive
with whatever degree of endorsement DMARC validation provides.

---rsk




[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]