

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Article is missing a note on the existence of MX records for the domains. Sure, you can easily have a send-only domain without an MX record, but the common case is likely to setup both send and receive capability. It would be interesting to have that number included as domains without MX and DMARC might just not be configured for email at all. Worst case the 45% of domains without DMARC are simply not relevant for email and thus not configured at all. I would find "x% of domains with configured email don't enforce DMARC" more interesting.by rft
- Technically you can receive mail without MX records if your mail server is on the same host as the web server.by account42
- I didn't see it explicitly mentioned in the post, I wonder if they filtered exclusively for domains with mx records. Because I would assume that lots of domains just don't have email configured and therefore aren't aware that you should still setup DMARC to prevent impersination of your domain.by agotterer
- The domains that do enforce DMARC are apparently configured so badly that the German secure email provider mailbox.org decided not to honor DMARC.
See this thread in German: https://userforum.mailbox.org/topic/10676-mailbox-org-akzept...
by asimops - Interesting thread. However, for over a year, the "secure email provider" did not reply more than that the consultants are too overloaded to reply...
The message you obviously refer to as just an educated guess by a forum user who seems to be experienced in email topics. It could be that the guess is correct. It could be hat the consumtants are too overloaded to configure things differently. Another user has that guess. We don't know as long as the provider does not answer.
by usr1106 - Using DMARC information is complicated in practice in the real world, by Chris Siebenmann
https://utcc.utoronto.ca/~cks/space/blog/spam/DMARCPractical...
- 403 errorby inigyou
- I am running email server for my private domain using https://github.com/docker-mailserver/docker-mailserver . One day in 2023 i decided that beside of dkim i maybe should also enable dmarc. Because ... well, why not. What happened was that i started reciving regular reports over email from ms and google containing compressed xml containing no info other that empty report was generated. What should I do with that? At that time i could not find any tool that would be able to extract valuable info from that, so I disabled dmarc. Havent looked back since.by raluk
- The reports are kind of useful when first enabling, if you want to get warnings about non-compliant mail, but after you're established, they're not really useful, so you should turn reports off, but you can do that without turning off the whole thing.by toast0
- There are lots of free tools that automatically analyze the reports for you (you send it to them, instead of yourself).
But if you send all emails for your domain from one email server, you could just disable rua reporting. The reports are mainly useful to see whether you have some misconfigired email server somewhere that causes (or will cause) dropped emails. That can easily happen if you send some email from your own server, some via sendgrid, some via some marketing tool, and start to lose track of them. But for a personal email server, that's not common.
by matharmin - I have set up DMARC, SPF, DKIM and whatnot. Sadly no one seems to take this as a signal for a competent mail setup, so Microsoft's mail servers regularly block my mails because of the surrounding IP range reputation - not because any spam would originate from my IPs or domains.by TonyTrapp
- Are you sending important or unimportant things?
When its unimportant or important to the receiver only, you push responsibility to them: "I sent it. Must be your email that's glithced. Tried Gmail or Proton?"
When its important to you, you use your backup Gmail or Proton account.
by inigyou - Email has been turned into a by-the-corporation, for-the-corporation service. Corporations need DMARC so they can control email and the ability to spam. The spam I cannot block is spam from Google.
If you decide to think about this, you will quickly realize that email is f*ked and needs to be forked. Perhaps we need a Community Email Initiative that blocks corporations and only allows Community members.
Trust is the one thing you can't buy on the Corporate Internet.
I am sure many people will be offended and down vote this comment because they cannot conceptualize an internet without Corporations.
by talkingtab - You can't solve a social or political problem with a technical solution. Whatever you invent, Microsoft and Google will still collude to block you and not each other.by inigyou
- What do you mean “fork”? Just buy a domain and install an email server.by 1over137
- No, email is the only digital communication left where I can talk to normie relatives AND businesses without having an account on normie tech service. DMARC does not impede that at all and it not a valid cause to throw away this lucky artifact of computing history.by account42
- You can already do this without changing anything. Just set your corporate mailserver to not accept mail from common community email providers. There's a reason nobody does this, and it's because it's a bad idea.
There is so much crossover between personal email and corporate email.
by thesuitonym - Yes, email is just completely broken. It's not private, sender identification is mediocre at best (and nonexistent without things like DMARC and SPF), and all the kludges thrown up make self-hosting harder. Spam has zero cost basically also. Nobody trusts email anymore for anything confidential, it's become a clumsy notification service "come check our portal for your real email".
It's time for a new protocol with end to end encryption and sender verification built-in. That shouldn't be as hard as it sounds, because at the time when email was invented the internet was very different. Connections were intermittent, for example I would retrieve my email once a day with UUCP (and some other people would use batched-SMTP). Which means you could not rely on the sending and receiving server being able to communicate directly. In this day and age this is possible and that direct communication opens up a lot of better crypto like key generation algorithms which require both parties to be online at the same time.
The problem is, is you don't allow corpos you will break 95% of mainstream people's usecases. So I think this is a non-starter, unfortunately, though it is a lofty goal.
by wolvoleo - You can do this right now, and you don't even need to fork anything. E-mail is an internet scale protocol that's not owned or ownable, except by convention. Since you specifically want to cut out Google, and their attempts to capture E-mail are what makes rolling your own E-mail hard anyway, just go for it.
Depending on how hard you want to make it, you can slap all the parts together yourself or use something like Zimbra, Mailcow, iRedMail, mail-in-a-box.
The advantage over a fork, whatever specifically that means, is any service that needs E-mail as an identity verification, still works.
by baron3dl - I really think we should be solving a much bigger problem of the major email providers not providing an automated way of handling abuse and not caring about abuse reports at all. Most of my spam comes from the three major email providers and at this point I gave up even trying to send abuse reports because they just get ignored.
The big companies do not have to care because nobody will block Google, Microsoft or Amazon. They are too big to fail.
Spoofing a From field is an insignificant problem in comparison.
by jwr - As a rule of thumb, big companies only listen to lawsuits.by inigyou
- Agreed, most spam has valid DMARC - whether that's bigmail.com or just nobodcarestoprotectsubdomains.randompwnedcompany.comby account42
- Not to mention that the larger companies are incentivized not to deliver your email due to low volume. If your service does not work, companies will be encouraged to use Google or Microsoft instead.by Freebytes
- Email providers do have an automated way of handling abuse. Send the message to abuse@provider and they automatically ignore it. =)by thesuitonym
- It's ironic that I set everything up correctly on my self hosted domain and still end up in spam because of my low volume.
I even go to the trouble of registering in their Postmaster Tools and clogging up my DNS with their verification tokens all for the tools to tell me I don't send enough mail while they happily pass what little mail I send straight to spam.
Each screen only shows: "No data was found for this domain."Not enough outgoing email You haven't sent enough email to personal Gmail (@gmail.com) accounts to determine deliverability status for your domain and messages.Guess it doesn't help that as I look today the Postmaster Tools dashboard shows "Last updated Sun, Apr 26, at 9:30 AM."
Then on the other hand Google can flood me with spam filled Google Calendar Invites and Google Drive Share notifications, all fully DKIM signed because they are coming out of those services, all day long.
Microsoft have also recently changed their Smart Network Data Service (SNDS) so now only my cloud provider can access the console as they only allow verification to the owner of the whole ASN block you're under. I can't access detail about my domain anymore, and still my mail goes to junk. Unless you own a chunk of IPv4 ASN range you're out of luck. IPv6? Nope, not at Microsoft. "Please note that IPv6 is not currently supported." [1]
[1]: https://substrate.office.com/ip-domain-management-snds/SNDS/...
by cube00 - The article speaks about DMARC monitoring, but not about "writing" it. So many orgs are too small to have someone paying attention of these things. Where I work, the CTO used to manage the DNS, but with very little understanding of what it all means. It was just copy and paste. And yes, it also says p=none. Probably because it was in the example. It's like setting up a website for your company, and picking some wordpress instance: how are you supposed to know the risks? It's just too much.by tgv
- LLMs are very good at helping you manage DMARC/DNS related configuration, even as a non-expert. I used it to develop custom DMARC report processing app that: 1. sucks in reports sent to our dmarc inbox into a sqlite db, 2. displays the results in a web page. The reports queue up in the mailbox and I open and start the app once a month to check the status. The agent also also reviewed the state of email-related DNS records, describe what needs to change, including how and why, and verify changes after the fact to ensure they are correct.
Some changes I made at the direction of an agent: fix domainkeys CNAMEs for M365, rotate M365 dkim keys that haven't been rotated for over a decade, fix broken spf record formatting.
My biggest issue is that squarespace refuses to enable dkim signing for transactional emails that they send for us (order/shipping confirmation etc). The email sending service they use (socketlabs) supports it but they are not interested in enabling the feature, so I can't lock down our dmarc. I guess that means squarespace is not a good fit for our needs; it's just disappointing that we have to move to a different platform again for technical reasons that are solvable with a dashboard switch.
by infogulch - If you have any domains that does not use email, it may be a good idea to set up some DNS records to prevent it being used.
DNS SPF record: mydomain.io. TXT "v=spf1 -all"
DNS DMARC: _dmarc.mydomain.io. TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s"
That ought to stop anyone trying to use your domains as source.
by TheChaplain - Isn't it default for domains without MX records, usually?by inigyou
- I use postfix and the recipient_access file to control email to my domains which use little email, so the domains are able to process standard email:
admin@example.com OK postmaster@example.com OK abuse@example.com OK webmaster@example.com OK hostmaster@example.com OK info@example.com OK example.com REJECT example.com
by newsoftheday