[Sca-cooks] Papa Gunther--- READ THIS!!!!!

Saint Phlip saintphlip at gmail.com
Thu May 8 09:24:51 PDT 2014


Hopefully, the new header will get gunther;s attention.

---------- Forwarded message ----------
From: Joel Lord <jpl at ilk.org>
Date: Thu, May 8, 2014 at 11:16 AM
Subject: Re: [Sca-cooks] List Test
To: Cooks within the SCA <sca-cooks at lists.ansteorra.org>
Cc: t.d.decker at att.net


Yahoo! and AOL have gone out of their way to break mailing lists.

http://www.ietf.org/mail-archive/web/ietf/current/msg87153.html

Yahoo! went first, AOL joined a few weeks later.

Since that article is _very_ dry, let me translate.  DMARC is a mechanism
for domains (yahoo.com, for example) to try and combat spoofing of their
address.  There are 3 "severity" settings: p=none, p=quarantine, and
p=reject.  Prior to early April, no one had used anything above p=none.

DMARC puts a signature into each email where you only see it if you know
where to look.  It's attached to the domain that sent the message, along
with a bunch of other bits and pieces like the Subject:.  Mailing lists
change the Subject:, so the signature is invalid... but the From: still
says yahoo.com, so it's yahoo.com's DMARC rules that apply.

EVERYONE who has even a p=none rule out there (which means they get
information and don't destroy email) will honor someone else's rule. That
is, att.net has a p=none so email spoofed to appear to be from att.net will
cause att.net to get notified.  But att.net will honor yahoo.com's
p=reject, so when att.net receives email that appears to be spoofed from
yahoo.com, they actually reject it.  This part is what bits most mailing
list users on the butt, since only 5% of people are still on AOL, and
something like 7% are still on Yahoo... but more like 75% of people are
using services that will honor this.

The fix?  ansteorra.org _desperately_ needs to upgrade their version of
mailman to newest (it only came out a few days ago) and turn on the DMARC
header munging features.  Also, they need to add lists.ansteorra.org to the
SPF record, since that's probably what's causing messages to get dumped to
GMail's spam folder.

I host 200+ mailing lists for 20+ not-for-profit organizations.  I've been
chewing on this since the beginning of April.  Hopefully someone here will
know who to forward this along to, since that one paragraph with the fix is
easy to do, but you only do it when you realize it is needed.


On 5/8/2014 10:25 AM, Doug Bell wrote:

> I am getting disable notices and missing my own posts along with not
> recieving other random posts. This is occurring with all of the lists on
> the Ansteorran server. Until they get their act together I am unsubscribing
> from all of their lists.
>
>
> Magnus
>
>
>
> ________________________________
>   From: Terry Decker <t.d.decker at att.net>
> To: Cooks within the SCA <sca-cooks at lists.ansteorra.org>
> Sent: Thursday, May 8, 2014 8:08 AM
> Subject: [Sca-cooks] List Test
>
>
> I've received a disable notice for bounces for an email address that was
> changed years ago.  I went to the mailing list page at ansteorra.org and
> found it disabled.  The list page can still be reached at
> http://lists.ansteorra.org/listinfo.cgi/sca-cooks-ansteorra.org.  The last
> archived message is from May 1.  So apparently we have problems at the
> server.  I'm putting this out to see if it comes back to me.
>
> Bear
>
>
> _______________________________________________
> Sca-cooks mailing list
> Sca-cooks at lists.ansteorra.org
> http://lists.ansteorra.org/listinfo.cgi/sca-cooks-ansteorra.org
> _______________________________________________
> Sca-cooks mailing list
> Sca-cooks at lists.ansteorra.org
> http://lists.ansteorra.org/listinfo.cgi/sca-cooks-ansteorra.org
>
>

-- 
Joel Lord
Web Administrator, Alpha Psi Omega Grand Cast
etc... etc... etc...

_______________________________________________
Sca-cooks mailing list
Sca-cooks at lists.ansteorra.org
http://lists.ansteorra.org/listinfo.cgi/sca-cooks-ansteorra.org



-- 
Saint Phlip

So, you think your data is safe?
http://www.cnn.com/2010/OPINION/01/23/schneier.google.hacking/index.html?hpt=T2

Heat it up
Hit it hard
Repent as necessary.

Priorities:

It's the smith who makes the tools, not the tools which make the smith.

.I never wanted to see anybody die, but there are a few obituary notices I
have read with pleasure. -Clarence Darrow



More information about the Sca-cooks mailing list