@cks sadly, "you'll have to ask Google why they threw your mail away" is rarely the answer people are looking for 🙂
Conversation
Notices
-
Embed this notice
Mythic Beasts (beasts@social.mythic-beasts.com)'s status on Friday, 31-Jan-2025 09:08:12 JST Mythic Beasts
- Haelwenn /элвэн/ :triskell: likes this.
-
Embed this notice
Chris Siebenmann (cks@mastodon.social)'s status on Friday, 31-Jan-2025 09:08:13 JST Chris Siebenmann
@beasts Yes, definitely non-DKIM email doesn't forward reliably even without DMARC policies. We've seen GMail reject non-DKIM signed email without an explicit DMARC policy on the domain; they seem to basically infer one. This isn't RFC compliant but they're the 800-kilo gorilla, what are we going to do.
-
Embed this notice
Chris Siebenmann (cks@mastodon.social)'s status on Friday, 31-Jan-2025 09:08:14 JST Chris Siebenmann
@beasts AFAIK DMARC doesn't normally require that the envelope sender passes SPF if From: is DKIM signed by the domain of the From: (what 'alignment' normally means in this context). We (a university department) successfully forward a lot of DKIM signed email to GMail despite not touching the envelope sender (so no SPF passing).
(People can creatively make their email non-forwardable (at least not easily) by having a narrow SPF and then no DKIM signature.)
-
Embed this notice
Mythic Beasts (beasts@social.mythic-beasts.com)'s status on Friday, 31-Jan-2025 09:08:14 JST Mythic Beasts
@cks yes, for DMARC you need an aligned SPF pass OR a DKIM pass. If you're forwarding, the former isn't going to happen, so you're reliant on DKIM. Sensible people don't enable strict DMARC policies without first ensuring that they're DKIMing everything, so that shouldn't be an issue, but forwarding mail that isn't DKIM signed (and lots still isn't) is unlikely to be reliable, even if the sender hasn't explicitly said "p=reject".
-
Embed this notice
Mythic Beasts (beasts@social.mythic-beasts.com)'s status on Friday, 31-Jan-2025 09:08:15 JST Mythic Beasts
After nearly drowning in an alphabet soup of anti-spam acronyms whilst trying to explain to a customer why email forwarding doesn't work, Kelduum decided to let off steam on our blog. https://www.mythic-beasts.com/blog/2025/01/29/the-death-of-email-forwarding/