logoalt Hacker News

brightballtoday at 3:35 PM1 replyview on HN

> virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks.

This should create a means to go after the domain owners via registrar and trail of ownership, even so far as blocking email from the domain.

Forcing the spammers to pass DMARC creates a burden and an evidence trail that didn't exist before.


Replies

bigbuppotoday at 4:26 PM

They're generally hosted on a google or microsoft 365 or something slightly less shady. Good luck with that.