Urgent.News

What's breaking now, across thousands of outlets.

Tech

How Mailing Lists Break DMARC, and Why ARC Only Partly Fixes It

Why mailing lists break DMARC, what ARC (RFC 8617) actually does about it, why it only helps where the receiver trusts the sealer, and why From-munging is the reliable fix.

How Mailing Lists Break DMARC, and Why ARC Only Partly Fixes It

Mailing lists and forwards often fail DMARC checks because they resend messages from their own servers. This breaks both SPF and DKIM authentication, and any modifications like added headers or footer content invalidate the author's signature. DMARC fails when the receiver rejects the message. A proposed solution is ARC (Authenticated Received Chain), which aims to keep the author's identity intact.

However, ARC alone does not provide a complete fix. Its effectiveness depends on the receiver trusting the sealing domain, which may not be universal. ARC also has limitations, such as not being evaluated by all servers and not having a global trust registry. The best approach is to use both techniques: ARC for receivers that support it, and From-munging as a backup for domains that publish strict DMARC policies.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

More from Saturday 15 August →