Hacker News new | ask | show | jobs
by jchook 1766 days ago
DMARC basically breaks mail intermediaries and is fundamentally problematic, hence the low adoption rate.

ARC is a much better alternative that builds on DKIM and allows intermediate custodians of mail.

2 comments

No it doesn’t, unless said intermediaries are modifying contents and are not DMARC aware.

Many European countries are forcing DMARC adoption for government infrastructure and it works just fine.

What does intermediate custodian mean here? Something like sendgrid? Is there an issue for normal peoples email on custom domains (eg fastmail or gmail hosted)?
I think he is talking about mailing list servers. When you email mailman, it'll add a line to the bottom of the email, manipulate some to: and cc: headers, and forward it along. This changes the hash of the email which breaks some crypto signatures.