helvede.net is one of the many independent Mastodon servers you can use to participate in the fediverse.
Velkommen til Helvede, fediversets hotteste instance! Vi er en queerfeministisk server, der shitposter i den 9. cirkel. Welcome to Hell, We’re a DK-based queerfeminist server. Read our server rules!

Server stats:

172
active users

#dmarc

1 post1 participant0 posts today
Continued thread

System Administration

Week 8, The Simple Mail Transfer Protocol, Part III

In this video, we look at ways to combat Spam. In the process, we learn about email headers, the Sender Policy Framework (#SPF), DomainKeys Identified Mail (#DKIM), and Domain-based Message Authentication, Reporting and Conformance (#DMARC). #SMTP doesn't seem quite so simple any more...

youtu.be/KwCmv3GHGfc

I just found out that Dovecot 2.4 is a crippled version of Dovecot 2.3: no more clustering support, the director function has been removed. If you want to do clustering now, you'll have to buy a Pro license.

https://doc.dovecot.org/2.4.0/installation/upgrade/2.3-to-2.4.html#removed-features

So, although I've used Dovecot for years, both private and for work, it seems like this is the end of the line for me.

At the same time I see what @Stalwart Labs can do. Yes, clustering, for one. And a whole lot more, including bayesian classification, analysis of DMARC reports and even a reputation database.

I'm really impressed by what it can do. Bit hesitant about the fact that it's still only version 0.11.5 though, smells alpha...

Looks like Stalwart is the future for me.

https://stalw.art/docs/cluster/overview

#Dovecot #Stalwart #E-mail #DMARC
doc.dovecot.org2.3 to 2.4 | Dovecot CEDovecot CE Documentation

Hey everyone! Big news: the PCI DSS 4.0 deadline is coming up fast! This time, DMARC is becoming mandatory for *anyone* handling credit card data. I know, it sounds like a pain, but trust me, it's *super* important. Phishing is still a massive threat, unfortunately. 🙄

So, what's the deal with DMARC? Think of it as a bouncer for your inbox. It helps block those sneaky, fake emails. Seriously, without DMARC, your company's basically an open invitation for cybercriminals. 🚪

A lot of folks are probably thinking, "Nah, doesn't apply to me." Nope! Even small businesses *have* to implement DMARC. It's a must-do! 💪

Now, I'm curious: Do you guys already have DMARC set up? And if you do, what tools are you using? Let's share some insights! 🤔

My emails are often flagged as 'spam' for my recipients, notably on mailing lists. I've set everything up hopefully correctly (DKIM, DMARC, etc.) and I score 10/10 at mail-tester.com/ . I don't appear to be on any block list, and I own my domain (goffi.org) for over 20 years.

Any ideas what the problem might be?

www.mail-tester.comNewsletters spam test by mail-tester.commail-tester.com is a free online service that allows you to test your emails for Spam, Malformed Content and Mail Server Configuration problems

Let’s not.

#DMARC adds value to email for very few entities and adds yet another way for email to break, if you let it. One of the hottest threads on the MailOp list right now is in regard to Mimecast mishandling mail in a way that breaks mail signatures, dependent on the encoding a MUA chooses for a message.

I have spent many hours debugging other people’s DMARC deployments. These are rarely billable hours and are deeply tedious. ioc.exchange/@percepticon/1133

IOC.exchangeMatthias Schulze (@percepticon@ioc.exchange)Attached: 1 image Time to Get Strict With DMARC https://www.darkreading.com/cybersecurity-operations/time-get-strict-dmarc?utm_source=dlvr.it&utm_medium=mastodon #cybersecurity #infosec

#MalwareBytes, an #infosec company, has allowed their #DMARC aggregate reports mailbox to fill multiple times in the years I've been interacting with them.
Reliable processes are a foundational requirement of successful #cybersecurity.
Reliable monitoring is also a foundational requirement.
Ensuring your organization doesn't make the same mistake multiple times? Also foundational.
I don't trust MalwareBytes, and you probably shouldn't either.

Fucking #Comcast is (again) bouncing emails from my family mail server with no explanation of why or what to do about it. Just "554 server not available".
There is no legitimate reason to bounce emails from my server. I do _everything_ correctly (incl. #DKIM and p=reject #DMARC) and my server has been in continuous operation for over a decade.
Comcast is the worst, but, they're not the only one pulling this crap.
Yet another domain I have to route through #MailGun. *sigh*
#smtp #sysadmin

Shout out to @mwl and his latest (digital presale) release, Run Your Own Mail Server (#RYOMS). Going to start reading it here shortly!

I have been an early adopter and mostly self-taught with #dmarc, so I've been looking forward to this release.

Michael has been a remarkable author of tech / security books over the years, in my humble opinion. I've learned a lot, and greatly appreciate the library of books I have of his 🙂

Lastly, his fiction work is quite entertaining as well!

Inwiefern ist DMARC und insbesondere sind dessen Report-Formate aggregate und forensic mit den Anforderungen der DSGVO vereinbar? Katharina Küchler (Anwältin, eco Verband) und ich (E-Mail Experte, Leiter Kompetenzgruppe E-Mail eco) sind dieser Frage im vollständig überarbeiteten Rechtsgutachten des #eco Verbandes nachgegangen.

Möge es für alle hier von Nutzen sein!

Deutsch:
eco.de/download/238585/

Englisch:
international.eco.de/download/

#DMARC#SPF#DKIM