[opendmarc-users] OpenDMARC NOT useless with Postfix

Chris Meidinger chris at agari.com
Thu Sep 18 16:25:24 PDT 2014


On Sep 18, 2014, at 18:21, Christian Rößner <c at roessner-network-solutions.com> wrote:

> Sorry for this. Just to get it right with SPF: if it does not use the From-header, is it the envelope from, while a MX its delivering mail? In session decision? Can you help clarify this?

No worries, man.

Yes, SPF uses the envelope from, or RFC5321.From. One of the new things with DMARC is that it requires the organizational domain (http://tools.ietf.org/html/draft-kucherawy-dmarc-base-04#section-3.2) in the envelope from to be related to the organizational domain in the From: header, or RFC5322.From.

SPF checking can be done on initial connect after MAIL FROM, before data transfer. DMARC checking, otoh, can only be done after the DATA phase because it needs the DKIM signature and full body of the message to validate the signature.

Ergibt sinn?

Chris




More information about the opendmarc-users mailing list