Conversation

Bringing security to existing ecosystems is delicate. All user pain must be: 1) aggressively minimized (by design, tooling or tradeoff) 2) justified by a security gain (more concrete the bigger the pain) 3) effectively communicated (if you do x, you get benefit y)
1
28
More emergent damage of DMARC: since it forces the envelope MailFrom to be the same as the From header (for no good reason, since it's meant to protect the latter, and the former is invisible), my newsletter bounces are now going to my FastMail inbox instead of Mailgun ¯\_(ツ)_/¯
3
6
Replying to and
It's incredibly painful if you involve other parties in it because they don't do things correctly. It's easy if you're sending all the mail yourself. Mailing lists need to be designed for compatibility with it by having you send mail to it and forwarding it along untampered.
1
1
They can add non-oversigned headers like List-Unsubscribe or other list-related headers. If they mess with the body or the signed headers they break it. If they send the mail entirely themselves then they need a working way to support that on your domain like adding DKIM keys.
1
1