Conversation

Gmail still explicitly permits anyone to send spoofed emails from Gmail users via their p=none DMARC policy. When is this going to be fixed? It's long overdue. To confirm `drill _dmarc.gmail.com TXT`. "v=DMARC1; p=none; sp=quarantine; rua=mailto:mailauth-reports@google.com"
3
23
You’re unable to view this Tweet because this account owner limits who can view their Tweets. Learn more
No, it doesn't. It only breaks mailing lists spoofing emails. As long as the mailing list only adds headers like List-Unsubscribe, the DKIM signature remains valid and it passes DMARC verification. Only misconfigured mailing lists would be broken, and they already are broken.
1
1
You’re unable to view this Tweet because this account owner limits who can view their Tweets. Learn more
What mailing list do you use that's still broken with DMARC in 2020? Mailing list software was updated to deal with this a long time ago. You don't seem to be up-to-date with the status quo. You're talking about it as if it's still years ago and the software is still broken.
2
Show replies
Mailing lists should be operating based on headers like List-Unsubscribe. If they INSIST on modifying signed headers and the content of the email, they need to change the address the mail claims to be from and can indicate the sender of the original email that they modified.
1