Hacker News new | ask | show | jobs
by lstodd 1766 days ago
SPF, DKIM, DMARC... all useless.

I somehow live without all those for what, since before they appeared. 2001 in fact. With my own MX.

They are just ineffective bandaids.

4 comments

As long as you don't email anyone who uses a gmail address or uses google's email hosting (which is the majority of internet users now?) then you can get away with that. I did too (also having run an MX since around 2001)... but a year or so ago google started filtering all email which didn't comply into spam.. so.. had no choice but to set it up.
What's with Google? It's not like Google is the Internet.

About everyone I feel a need to connect with understands that, so they don't use gmail, at least exclusively.

If a company trying to hire me can't receive email from me "because google" - then to hell with them, period. They are incompetent.

Although I must say there were no lost, rejected or diverted to spam messages from my deliberately ignorant MX to gmail for the last year.

Everyone I know who isn't tech-literate uses Gmail because (a) Gmail is/was better than their ISP's email in many ways, including UI and spam filtering, and (b) it's hard to switch off without dedicating a few hours to changing your email on a bunch of services (and there are a lot of services that don't offer email changes at all) - also, if someone hasn't use a password manager religiously, chances are they don't even have a convenient list of all the services they're signed up for.
83% of spam I received last month failed at least one of these checks, while less than 2% of ham did. They're certainly useful.
IDK maybe it's my tendency to keep a low profile. Or some other perceptual bias.

But in last 5 years levels of spam never even remotely approached levels what I remember from 2000s, when my job was actually fighting it (at an ISP).

All this tech (SPF, DKIM, DMARC) came and went ... somewhere, and there was exactly zero impact in spam rates on the handful of domains I now maintain, when I did take some time to implement them.

Nowadays I have a couple of my own domains, with nothing antispam-configured, and an gmail account, and you know what -- spam amounts almost exactly match.

Hence the conclusion - it's not worth it to invest time into it.

Maybe try running a business?
The point of these is to tie email reputation (aka. How much spam you send) to the domain sending the mail instead of the IP address doing the sending. You can still send mail without these set up, but real spammers might see it missing and impersonate your domain in their spam and tank your reputation.
Yet without DMARC, we would be far worse off.
I doubt that.