logoalt Hacker News

kamma4434today at 1:07 PM4 repliesview on HN

And what is the sane way to handle a spoofed email?


Replies

thesuitonymtoday at 2:20 PM

`p=reject`, ESPECIALLY for your personal email. `p=quarantine` is really only useful if you suspect your marketing department has set up some email blaster somewhere.

winstonwinstontoday at 2:11 PM

Realistically spoofed address (unauthenticated email) will be treated as spam and it’ll be implicitly quarantined or rejected as such by many well-known mail receivers. You can make this an explicit “reject” by publishing DMARC policy for your domain.

For example, gmail.com treats unauthenticated email as spam implicitly, regardless of DMARC policy.

azeembatoday at 1:11 PM

That's what the policy setting tells the recipient. You can tell them to trest it as normal, send it to spam or delete it.

The report that they send you is useful for you to make sure your emails that you expect to go through are going through.

toast0today at 3:20 PM

Reject it in the SMTP transaction.