[opendmarc-users] Can I tell why a specific message failed?

Benny Pedersen spf at forged.junc.eu
Tue Aug 26 11:26:00 PDT 2014


On 26. aug. 2014 18.01.05 "Dan Mahoney, System Admin" 
<danm at prime.gushi.org> wrote:

> Those zones aren't signed, and I don't think I've seen any requirement in
> the spec, or the FAQ, or anywhere else that says DNSSEC is mandatory.

I have no rfc at hand here, but i changed from org tld to eu tld to solve 
it for my problem at org tld

The example dkim pass could still be forged when its not dnssec

> (although of course a good resolver should reject a record with a DNSSEC
> sig failure -- that's not what's happening here).

There is 100 ways to make it incorrect, but just one to make it right


More information about the opendmarc-users mailing list