Conversation

Gmail still explicitly permits anyone to send spoofed emails from Gmail users via their p=none DMARC policy. When is this going to be fixed? It's long overdue. To confirm `drill _dmarc.gmail.com TXT`. "v=DMARC1; p=none; sp=quarantine; rua=mailto:mailauth-reports@google.com"
3
23
You’re unable to view this Tweet because this account owner limits who can view their Tweets. Learn more
No, it doesn't. It only breaks mailing lists spoofing emails. As long as the mailing list only adds headers like List-Unsubscribe, the DKIM signature remains valid and it passes DMARC verification. Only misconfigured mailing lists would be broken, and they already are broken.
1
1
Don't send emails falsely claiming to originate from another address and it's not an issue... that's the feature working as intended, and as it should work. It shouldn't be possible to send spoofed mail whether or not it's a mailing list. Not at all needed to have a working list.
2
1
You’re unable to view this Tweet because this account owner limits who can view their Tweets. Learn more
You’re unable to view this Tweet because this account owner limits who can view their Tweets. Learn more
DMARC doesn't break mailing lists. Mailing list software was updated to either avoid breaking DKIM signatures by not tampering with the emails or to mangle the From address to refer to the mailing list server since that's where that email was actually created if they modified it.
1
1
Show replies
Perhaps they should update to address serious security vulnerabilities and other bugs if they really haven't updated their mailing list software in that long. You'd need to explicitly configure mailman, etc. to break this by tampering with emails without mangling From address.