mastodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance, open to everyone, but mainly English and French speaking.

Administered by:

Server stats:

857
active users

#dmarc

0 posts0 participants0 posts today

Has anyone here on #fedi figured out the correct recipe for dealing with #OpenPGP, #DMARC and #mailman ?

The problem, by default mailman will modify messages and this will break the dkim signature.
gitlab.com/mailman/mailman/-/i

Mailman provides two DMARC mitigation options (other option is reject or discard which is not useful in this case).

1. Replace the from address with list address
2. Wrap original message in an envelope

thunderbird flags 1 and fails 2.
#askfedi #gnupg #gpg #thunderbird

GitLabAdd DMARC conformity mode (do not modify DKIM signed headers and body) (#1079) · Issues · GNU Mailman / Mailman Core · GitLabCRITICAL I deployed mm3 to my e-mail server working with the large Linux developer community and we are facing DMARC issues [1]. It seems that...

Hey everyone! Big news: the PCI DSS 4.0 deadline is coming up fast! This time, DMARC is becoming mandatory for *anyone* handling credit card data. I know, it sounds like a pain, but trust me, it's *super* important. Phishing is still a massive threat, unfortunately. 🙄

So, what's the deal with DMARC? Think of it as a bouncer for your inbox. It helps block those sneaky, fake emails. Seriously, without DMARC, your company's basically an open invitation for cybercriminals. 🚪

A lot of folks are probably thinking, "Nah, doesn't apply to me." Nope! Even small businesses *have* to implement DMARC. It's a must-do! 💪

Now, I'm curious: Do you guys already have DMARC set up? And if you do, what tools are you using? Let's share some insights! 🤔

✉️ Le courrier électronique est une cible privilégiée pour le spam, le phishing et autres formes d'escroqueries.

👩‍🏫 Découvrez DKIM, DMARC et SPF, trois techniques d’authentification de l’émetteur qui s’inscrivent dans la boîte à outils des organisations qui cherchent à lutter durablement contre ces abus.

Prochaines sessions :
📅 27 et 28 mars 2025
📅 22 et 23 mai 2025

➡️ Découvrez le programme complet et inscrivez-vous ici : afnic.fr/produits-services/for

Continued thread

now also available in English:
DMARC mail security protocol gets an update -- New tags added, old tags dropped, and a new alignment and discovery algorithm introduced
sidn.nl/en/news-and-blogs/dmar

The main differences between the updated protocol and the current version are the inclusion of three new tags, the withdrawal of three existing tags, and replacement of the algorithm used for DMARC policy discovery and alignment by a new algorithm.

One of the clients that I work with uses MailChimp. Got their domain validated with DNS records and after they were pitched on the ValiMail dmarc service.

I wasn't familiar with it before.

Anyone has experience with this kind of service?

Looks like you can use it to monitor what emails are sent using your domain. Not sure that is needed.

On their webpage it says that they partner with Microsoft and Google. That makes me trust them less, not more.

Are alternatives like PowerDmarc worth checking out? They tout "ai" as a part of their technology, which also does not inspire trust.

https://www.valimail.com/

#email #valimail #dmarc #powerdmarc
Valimail - · Leading Email Authentication Solution | ValimailProtect your business from phishing and spoofing 4x faster with Valimail’s automated DMARC, DKIM, and SPF email authentication solutions.

op SIDN.nl:
DMARC-beveiligingsprotocol voor mail krijgt een update -- Nieuwe tags erin, oude tags eruit en een nieuw alignment-zoekalgoritme
sidn.nl/nieuws-en-blogs/dmarc-

De belangrijkste wijzigingen betreffen de introductie van drie nieuwe tags, de uitfasering van drie bestaande tags, en de vervanging van het zoekalgoritme voor de DMARC-policy en alignment door een nieuw algoritme.

𝐇𝐨𝐰 𝐭𝐨 𝐬𝐞𝐜𝐮𝐫𝐞 𝐲𝐨𝐮𝐫 𝐞𝐦𝐚𝐢𝐥 𝐰𝐢𝐭𝐡 𝐒𝐏𝐅, 𝐃𝐊𝐈𝐌 𝐚𝐧𝐝 𝐃𝐌𝐀𝐑𝐂

Email is usually a critical part of corporate communication these days. Without a functional email, companies can lose orders and therefore money for example. Therefore, email security should be a very high priority. But equally, increasing email deliverability should be very important.

In today's video, we'll look at how to increase email security from the perspective of protecting your domain. In other words, so that an outsider can't impersonate you, send emails under your domain, and thereby damage your company's reputation or credibility by, for example, sending out spam or, heaven forbid, fake invoices for payment from your domain.

We'll also look at how to increase the deliverability of your messages. That is to say, so that regular emails leaving your domain are delivered to the recipient, and don't fall into spam or get completely thrown away by the recipient's mail server.

We'll focus on three basic options for email security and deliverability that every organization should have implemented.

📺 Watch my YouTube video bellow 👇 👇
youtu.be/xtmDDl1rjOc