techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

5.3K
active users

#whatever

2 posts2 participants1 post today
Replied in thread

@grumpybozo : I definitely am not angry with you (I very much agree).

Unfortunately many admins treat security solutions like they're a religion.

Some time age there was a hefty debate on a Dutch "mostly admins" site (tweakers.net, I'd have to look up the exact thread) about the "correct" sending and receiving MTA configurations. There was no agreement.

Microsoft even used to ignore SPF/DKIM/DMARC if the sender was in the "safe senders" list (which the user's address book defaults to). What could possibly go wrong (later MS corrected that).

The screenshot below is from part of security.nl/posting/766069/DMA (I wrote that Sept. 14, 2022).

Edited 23:36 UTC to add: {
arxiv.org/abs/2302.07287
Forward Pass: On the Security Implications of Email Forwarding Mechanism and Policy
Enze Liu, Gautam Akiwate, Mattijs Jonker, Ariana Mirian, Grant Ho, Geoffrey M. Voelker, Stefan Savage
}

#SPF#DKIM#DMARC
Replied in thread

@deepthoughts10 wrote: "email authentication like DMARC/SPF does one thing: it prevents impersonation of a specific domain (assuming policies are configured for reject or quarantine.)"

It does not even do that on my iPhone.

P.S. SPF was invented to prevent Joe Jobs (en.wikipedia.org/wiki/Joe_job). Marketing idiots (including Bill Gates) said that it would kill spam. It killed forwarding instead.

@grumpybozo @jwz

#SPF#DKIM#DMARC