Hacker News new | ask | show | jobs
by brightball 20 days ago
DMARC isn't for sending email successfully, it's for preventing other people from impersonating your domain. Without it, there's nothing stopping anybody from sending an email saying it is from you@qurren.com. SPF tried. DKIM tried. Both of them had gaps.

When you use them together and have a DMARC policy that requires one of them or the other for successful delivery, it's the best current solution.

2 comments

Right, and when you don't configure DMARC successfully and the recipient requires DMARC, then you cannot send email successfully.
Yeah. And when you don't configure your TLS certificate correctly, people can't connect to your webpage.

The anti-email authenticity standards gang has always smelled like the anti-TLS gang to me.

That's a feature, not a problem.
Except I think I've had 1:1 personal e-mails from my domain go into a legitimate recipient's spam filter just because I didn't have DMARC set up and their mail server was flagging that "DMARC not set up == spammy domain"
That is perfectly reasonable. Set it up correctly.
It is so much easier to set these things up with a frontier AI to walk you through the Byzantine steps.
It takes an afternoon to set up DKIM and DMARC from scratch on a debian VPS. Yeah it's a little bit byzantine but it's not rocket science.
Yeah I did that. Now it seems I have to set up DKIM2 and DMARC2 and DCRAP3 and DSHIT4 for another afternoon instead of just going to work and getting shit done.
Good heavens an entire other afternoon after a decadal standards update. You’ll have to spend an afternoon upgrading off XP at some point too.
Too many admins just had it set to “no valid DMARC? Spam” instead of the more proper “failed DMARC? spam”.

Which is subtly different.