toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

375
active users

Taking a stroll through my spam folder, I saw a bunch of legitimate messages from people and companies with their own domains, that are not publishing DMARC and SPF records. Surely everyone (and by everyone I mean Google) is rejecting their mail? How do they not realize this?

Then I noticed that one of them was received *from* gmail, so their mail probably works fine so long as they only mail gmail users. But another was via Yahoo, so that doesn't track.
jwz.org/b/ykk8

@jwz The stats we collect for the project (mass-scan results from participating sites) have long shown that spammers are more consistent at making SPF, DKIM, and DMARC correct than are legitimate senders. DMARC in particular has no discernible benefit for most senders, so it is a useless signal.

Rejecting mail based solely on authentication failures of those deeply flawed authentication methods does more harm than good.

@grumpybozo Wow, that's amazing. Great job everybody! So glad we spent so much time implementing all of that crap!

@jwz @grumpybozo just one more public key in a TXT record, that'll fix email, just gotta add one more TXT record bro

🆘Bill Cole 🇺🇦

@atax1a @jwz It is a frustration that for DKIM, DMARC, and SPF to be as trustworthy as possible, one must deploy DNSSEC correctly and defend one's domain against any threat to its reputation but all the spammers need to do is buy a cheap domain with any old garbage DNS and get a handful of records right.

@grumpybozo @jwz and don't get us started on how dnssec is untroubleshootable garbage whose main failure mode is to turn your entire domain into an unresolvable sinkhole

@grumpybozo @atax1a @jwz Intent of SPF was to get to the point that a domain reputation system of some kind would be viable. If someone outside of Google et al built one, it would be.

@nwp @grumpybozo @jwz none of this is true or follows from the premises, hth