Amusing :) Although I have to admit that I am even less sure after using that site. There doesn't seem to be an indication that DKIM "FAIL" in red is a good or bad thing after it attempted to spoof a domain I own. I assume it's good?
A spoofed message should FAIL DMARC. It could PASS DKIM and if the signature came from a domain that is owned by the attacker. But DMARC will fail when the DKIM domain and the HEADER.FROM domain do not align.
Comments
When you manage your domains through Fastmail it does it automatically. I certainly haven't had to configure it myself.
There is a neat website to check your email settings that was on the HN front page earlier this year:
https://www.learndmarc.com/
Amusing :) Although I have to admit that I am even less sure after using that site. There doesn't seem to be an indication that DKIM "FAIL" in red is a good or bad thing after it attempted to spoof a domain I own. I assume it's good?
A spoofed message should FAIL DMARC. It could PASS DKIM and if the signature came from a domain that is owned by the attacker. But DMARC will fail when the DKIM domain and the HEADER.FROM domain do not align.
Please read my blog here: https://www.uriports.com/blog/introduction-to-spf-dkim-and-d...
It will explain how SPF, DKIM, and DMARC work together to prevent spam.
Not sure, I can't say I'm super familiar with this. Which I guess is part of the reason I'm having it configured through Fastmail.
This is the original submission where the link came from if it helps:
https://news.ycombinator.com/item?id=29869266