Conversation

Bringing security to existing ecosystems is delicate. All user pain must be: 1) aggressively minimized (by design, tooling or tradeoff) 2) justified by a security gain (more concrete the bigger the pain) 3) effectively communicated (if you do x, you get benefit y)
1
28
Replying to
Ha, if you look through my Twitter feed I discussed this in detail a few months ago… Google, for example, expects you to recurse their include: statements but does not do it to yours, same for others. SPF & DMARC, which are a good idea, turned into weapons to force you to borg.
2
3
SPF is a legacy thing which doesn't really work properly. It can be used to pass DMARC but there's never really a case where you should need it to pass. SPF itself will pass as long as MAIL FROM passes SPF and just won't contribute to passing DMARC if it doesn't pass for FROM.