xakan, to random French
@xakan@social.zdx.fr avatar

Avec quoi vous gérez sur votre serveur mail ?
ne semble plus maintenu. Un remplaçant ?

ouvaton, to random French
@ouvaton@ouvaton.coop avatar

📢 Nous disposons maintenant du trio indispensable pour authentifier et sécuriser la totalité des mails expédiés depuis nos serveurs : SPF, DKIM et DMARC.

Grâce à ces trois protocoles, la délivrabilité de vos mails est encore améliorée avec toujours moins de risque d'un classement comme spam 🥳

Merci à @Octopuce pour l'aboutissement de ce projet de longue date, qui nous permet de proposer une plateforme mail plus fiable que jamais ! 😍

hisham_hm, to random
@hisham_hm@mastodon.social avatar

How spoofable is an email From: field nowadays?

I know that back in the days of POP3 and unencrypted email you could write anything in From: and one would have to cross-check with the other headers to see if the message at least went through the domain in the address.

I believe nowadays big servers like gmail are stricter in the email they accept (to the point of rejecting valid emails, which is super annoying, I know), but is there a standard in check that foo@bar.com comes from bar.com?

jomo,
@jomo@mstdn.io avatar

@kinnison @hisham_hm does help against spoofing headers such as "From:", and the mail body. It comes with the major caveat (amongst others) that once leaked, you have no way* to plausibly deny authorship of emails. IIRC this has happened with Hillary Clinton's mails on Wikileaks.

*you can regularly rotate your signing keys and publish the old keys, however there does not seem to be a standard way of doing this.

2/3

patrickbenkoetter, to email German
@patrickbenkoetter@troet.cafe avatar

Inwiefern ist DMARC und insbesondere sind dessen Report-Formate aggregate und forensic mit den Anforderungen der DSGVO vereinbar? Katharina Küchler (Anwältin, eco Verband) und ich (E-Mail Experte, Leiter Kompetenzgruppe E-Mail eco) sind dieser Frage im vollständig überarbeiteten Rechtsgutachten des Verbandes nachgegangen.

Möge es für alle hier von Nutzen sein!

Deutsch:
https://www.eco.de/download/238585/

Englisch:
https://international.eco.de/download/238605

EricCarroll, to email
@EricCarroll@mastodon.acm.org avatar

If you use forwarding actively, HEADS UP.

is now enforcing policy and as of midnight last night is bouncing email from ACM.ORG addresses that did not come through the ACM Relay service.

You need to change your email configuration to use the ACM SMTP Relay service immediately.

Here is a link for how to configure your mail service (including GMAIL) for the Mailroute SMTP Relay.

https://support.mailroute.net/hc/en-us/sections/5551581660819-Configuring-Email-Client-Software-for-MailRoute-s-Outbound-SMTP-Auth-Service

afnic, to random French
@afnic@mastodon.social avatar

🗓️ Formation en ligne "Sécuriser son courrier électronique grâce au DNS avec DKIM, DMARC, SPF" avec @bortzmeyer les 28 et 29 mars 2024.

ℹ️ Programme et inscriptions sur https://www.afnic.fr/observatoire-ressources/agenda/formation-securiser-son-courrier-electronique-grace-au-dns-avec-dkim-dmarc-spf-4/

stuartl, to email
@stuartl@longlandclan.id.au avatar

Fun and games with email today… Yahoo and Google have stepped up their filtering game, requiring stricter DKIM/DMARC.

That broke my workplace email addresses.

Consequently, I wound up reviving my old yahoo.com.au email address… fun and games remembering the password to an account I haven't used regularly in the better part of 25 years.

Thankfully, I must've logged in more recently, and changed the password… and crucially, stored it in the password manager. So it's working again.

My home mail server: delivers to the old Yahoo account, no problems at all.

Meanwhile, Office365 + MailGuard… crickets chirping.

SPFv1 for both work's domains are correct, how the hell does a hobby server admin like me get something right that professionals like Microsoft get wrong?

patrickbenkoetter, to random German
@patrickbenkoetter@troet.cafe avatar

An alle, die mit E-Mail zu tun haben und die es amtlich richtig™ machen wollen: Das @bsi hat die Technische Richtlinie BSI TR-03182 „Email Authentication“ https://bsi.bund.de/dok/tr-03182-en veröffentlicht, welche beschreibt wie , und eingesetzt werden müssen, damit sie konform mit der TR sind und einen Audit für eine BSI-Zertifizierung bestehen können.

Weshalb ich das schreibe? Ihr lest den troet des stolzen Autors, der 1,5 Jahre mit dem BSI an der TR getüftelt hat.

shuttersparks, to random
@shuttersparks@qoto.org avatar

Seems odd to me that there are, apparently, no discussions on Mastodon about Zoho.

I've been using them for 14 years and they have about 100 million users.

fredonline,
@fredonline@fosstodon.org avatar

@shuttersparks I've mentioned Zoho recently. 🙂

I suspect that, with both Gmail and Yahoo recently tightening up on authenticated emails, some Zoho users may begin to notice their emails are being rejected and may no doubt blame Zoho for the problems!

riastradh, to random
@riastradh@mastodon.sdf.org avatar

Do you run a mail server, or own a domain example.com that you send mail from?

PSA about the Coming DKIMpocalypse on Thursday when Google and Yahoo tighten mail rules:

https://support.google.com/a/answer/81126?hl=en
https://senders.yahooinc.com/best-practices/

1/3. The mail server must sign outgoing mail with DKIM. You generate a key pair called “foo” (e.g., with opendkim-genkey), configure your mail server to use it, and publish the public key in the DNS like:

foo._domainkey.example.com. IN TXT (
"v=DKIM1; k=rsa; "
"p=..."
)

xdydx,
@xdydx@mastodon.social avatar

@dalias
Cheers. In context of your other reply this makes sense and makes @riastradh post much clearer!

So effectively there is a school of thought that says for to be both effective and not a threat you would need to be able to
• generate a private key per email
• insert it into the header
• sign the entire message
• publish the dkim record during transit
• profit...

link2xt, to email
@link2xt@fosstodon.org avatar
jschauma, to sysadmin
@jschauma@mstdn.social avatar

Hey Fediverse! The Spring semester is about to start, and I'll be teaching System Administration again:

https://stevens.netmeister.org/615/

Topics covered include: basic operating system & filesystem concepts, software installation & package management, config management, automation, tools development, TCP/IP networking, common services, system security.

All lectures are online as free videos; if you'd like to follow along, here's the playlist for Week 1:

https://www.youtube.com/playlist?list=PLDadzdouM0VCV7tjurqM8FHY6APK9wvJl

jschauma,
@jschauma@mstdn.social avatar

After this week's Spring Break, we return in my class to dive into .

We start with an overview of the ecosystem consisting of MUAs, MTAs, MDAs, Access Agents, and tcpdump a simple manual SMTP session over telnet. We then talk about STARTTLS, MTA-STS and , before diving into defenses, including , , and , all with practical examples, tracking lookups and traffic on the sender and receiver.

Video lectures here:
https://youtu.be/Ai8rjqelwsI?si=7_4JnfwHwvFDShx_

jschauma, to random
@jschauma@mstdn.social avatar

Heh, request smuggling is no longer just for HTTP. Circumvent , , by smuggling commands (and thus spoof mail), because some MTAs don't strictly require \r\n.\r\n :

https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/

For , set smtpd_forbid_unauth_pipelining=yes:
https://www.postfix.org/smtp-smuggling.html

iammannyj, to random
@iammannyj@fosstodon.org avatar

In the wake of Google’s announcement of new rules for bulk senders, Microsoft is urging Microsoft 365 email senders to implement SPF, DKIM and DMARC email authentication methods.

https://www.helpnetsecurity.com/2023/10/09/microsoft-365-bulk-email/

fell, to sysadmin
@fell@ma.fellr.net avatar

I've successfully set up Mox by Mechiel Lukkien as my new mail server. It handles SMTP, IMAP, SPF, DKIM, and DMARC. It has a built-in spam filter, a web interface, webmail, autoconfiguration and it can show a checklist whether your DNS is set up correctly or not. All in a single binary! Pretty cool stuff. I'm planning to test various other solutions and document it on my blog soon.

#admin #sysadmin #mail #email #smtp #imap #dkim #spf #dmarc #dns #web #webmail #mox

afnic, to random French
@afnic@mastodon.social avatar
protonmail, to iOS
@protonmail@mastodon.social avatar

Good news for users - now you can activate automatic deletion for 🔥 spam and 🗑️ trash emails older than 30 days!

Start saving storage every month with one single tap.

Available on all paid plans: https://apps.apple.com/us/app/proton-mail-encrypted-email/id979659905

mjgardner,
@mjgardner@social.sdf.org avatar
adelgado, to Ansible
@adelgado@eu.mastodon.green avatar

Free afternoon meant to do an Ansible role to configure DKIM for my mail server. https://codeberg.org/adelgado/ansible-role-opendkim_postfix

LukaszHorodecki, to Blog Polish
@LukaszHorodecki@pol.social avatar

W tym tygodniu na „silva rerum” opis konfiguracji poczty na home.pl, tak by hostowany tam WordPress mógł wysyłać maile w formie przyjmowanej przez Gmail.

https://horodecki.net/2023/08/28/wysylanie-e-maili-z-wordpress-na-home-pl/

patrickbenkoetter, to random German
@patrickbenkoetter@troet.cafe avatar

Usage of RSA-SHA1 for was deprecated in 2016. Still about 1 % of all DKIM signatures use that insecure algo-hash combination. Check your key material if it is older than 3 years. Replace it with RSA-SHA256 and while you are at it add (!) ED25519 (RFC 8463) as a second type of signature algorithm if your software supports that. ED25519 has a significantly shorter bitlength, puts less load on DNS and speeds up processing.

shaft, to til French
@shaft@piaille.fr avatar

Les gens disent "déquim" poir

Toujours prononcé comme un acronyme (D.K.I.M) 🤔

Pourquoi je prononce comme cela alors que je parle par exemple de "Démarque" (DMARC), de l'Eau-nue et de l'Eau-temps 🤔🤔

bortzmeyer, to random French
@bortzmeyer@mastodon.gougere.fr avatar

Aujourd'hui, je suis à la campagne, pour la .

bortzmeyer,
@bortzmeyer@mastodon.gougere.fr avatar
zsoltsandor, to Vivaldi

Hey @Vivaldi noticed that vivaldi.net is one of the all-greens on Hardenize.
I'd move my mails to vivaldi.net, but I have size worries, still use other providers, & own domain.
Do you have any plans to implement paid size plan, & features like automatic IMAP fetch, external sending SMTP, own domain management?

BeerFox, to random
@BeerFox@mstdn.social avatar

I am going to point out now that I've been running my own mailserver for 15+ years

And I can't send mail to people with Apple or Google accounts. Why? Well, I'm not a known corporate entity. They whitelist email to known large businesses, an unrecognized IP gets blocked directly.

So y'know, yeah. Globally recognized protocol, got all the SPF/DKIM/DMARC/etc, but when it comes down to it, once big business gets a majority of an open protocol? They will devour it

cazabon,

@BeerFox

It's been a big for years, though it's getting . The / Outlook-Hotmail-Office365 / Yahoo triumvirate have backroom deals so they don't have issues to each other. But the small guys have trouble delivering to them - particularly Gmail.

I've run my own mail server for going on 25 years now. For the last 15 years it's had the same IP. Strict & , correct & . Zero . And I still have deliverability problems.

[...]

density, to asklemmy in A modest proposal: roundtable on defederation
density avatar

uuuummmmm it does

Cory Doctorow @pluralistic @doctorow
28 Apr 2022
TFW your self-hosted email server of 20+ years stops working because Gmail no longer accepts email from it.

https://nitter.kavin.rocks/doctorow/status/1519673852862771200#m

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • cisconetworking
  • thenastyranch
  • GTA5RPClips
  • everett
  • Durango
  • rosin
  • InstantRegret
  • DreamBathrooms
  • magazineikmin
  • Youngstown
  • mdbf
  • slotface
  • ethstaker
  • megavids
  • kavyap
  • normalnudes
  • modclub
  • cubers
  • ngwrru68w68
  • khanakhh
  • tacticalgear
  • tester
  • provamag3
  • Leos
  • osvaldo12
  • anitta
  • lostlight
  • All magazines