> On Dec 19, 2016, at 12:59 PM, Michael Richardson <mcr+ietf@xxxxxxxxxxxx> wrote: > >> A third choice is to configure the list to neither add footers, nor >> modify the subject line. At which point you're no longer breaking DKIM >> signatures, and DMARC passes. > > I don't understand how it can "pass". > It's still arriving from an IP address not listed in the SPF, claiming to be > From the provider. It passes DKIM, which is sufficient. SPF checks the envelope, and the list replaces the envelope sender with the list owner address, so SPF also passes (for the envelope sender, while DKIM validates the RFC2822.From). -- Viktor.