Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
M

moco

@moco
About
Posts
2
Topics
1
Shares
0
Groups
0
Followers
0
Following
1

Posts

Recent Best Controversial

  • Authentication-Results should also contain DMARC and DKIM result
    M moco

    New subscriber here.

    I wanted to request an email header enhancement. For incoming email, currently the "Authentication-Results" header only displays if SPF passed or failed. Other email implementations also place the DKIM and DMARC results there. I'm requesting the Cloudron email also place the DKIM and DMARC results in the Authentication-Results header.

    Authentication-Results: mail2.outsi.de (dis=neutral; info=dmarc domain policy);
        dmarc=pass (dis=neutral p=reject; aspf=r; adkim=r; pSrc=dns) header.from=example.org;
        dkim=pass header.d=example.org header.s=r header.b=O/8zOi6w
    

    I believe this available by adding OpenDMARC to Postfix.

    When fully functional this header is a useful troubleshooting tool for incoming emails.

    Feature Requests email

  • Authentication-Results should also contain DMARC and DKIM result
    M moco

    @girish Hi there. Thanks for checking into this for me.

    I had a suspicion that the spam engine was verifying, since I did see those fields in the Spam results headers. However I think it's also useful to have Haraka add the headers as well. It would add very little overhead and will add additional detail that the spam header doesn't contain about the DKIM verification (such as which signature failed or passed, since an email can contain multiple).

    In regards to DMARC. I don't believe this would be risky at all if implemented in the following manner:

    • No DMARC record found, take no action.
    • DMARC found, DKIM/SPF aligned, take no action
    • DMARC found, DKIM/SPF alignment fails, but p=none, take no action.
    • DMARC found, DKIM/SPF alignment fails, but p=quarantine, move to spam folder
    • DMARC found, DKIM/SPF alignment fails, p=reject, dev/null the mail. If you don't like the risk of this, push it to spam instead... or make it a cloudron option under Settings.

    Thanks for listening.

    Feature Requests email
  • Login

  • Don't have an account? Register

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search