On 04/22/2014 12:30, Eric Shubert wrote:
On 04/22/2014 07:39 AM, Kelly Cobean wrote:
If I'm way outside of scope here, please ignore my email. I thought
since EZMLM is part of the QMT build, I'd ask.
I have an EZMLM list that some yahoo users are members of. I also have
some gmail users. When yahoo users send to the list, the gmail users
aren't getting the emails.
One of my users got a bounce back with the following, and I was
wondering what, if anything, I can tweak in my config to overcome this
(email addresses removed for privacy):
Hi. This is the qmail-send program at mail.vipercrazy.com.
I'm afraid I wasn't able to deliver your message to the following
addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
<[email protected]>:
User and password not set, continuing without authentication.
<[email protected]> 74.125.196.26 failed after I sent the message.
Remote host said: 550-5.7.1 Unauthenticated email from yahoo.com is not
accepted due to domain's
550-5.7.1 DMARC policy. Please contact administrator of yahoo.com domain if
550-5.7.1 this was a legitimate mail. Please visit
550-5.7.1 http://support.google.com/mail/answer/2451690 to learn about
DMARC
550 5.7.1 initiative. 69si200255yhf.97 - gsmtp
---------------------------------------------------------------------
Dan or someone else might know more about this than me, but it
appears to me that google is enforcing yahoo's DMARC policy, which
apparently says that mail from yahoo isn't supposed to be coming from
your ezmlm server.
There's gotta some way for DMARC rules to allow for this. I'm
guessing that ezmlm makes the outgoing messages appear to be coming
from yahoo. Is there a configuration setting which would make them
appear to be coming from the ezmlm list instead? I'm guessing this
would bypass the DMARC check.
Anyone else have thoughts on this?
Yeah, my list server preserves the original senders email address when sending
to the list, just like qmailtoaster-list does. I figure people won't know who
an email is coming from if I don't. I'd change it if I have to, but preserving
the original sender email is ideal.
Upon some digging.....
http://www.mail-list.com/yahoo-dmarc-solution/?gclid=CJvT8s3U9L0CFe07OgodI3AAgQ
Sigh. Freakin' Yahoo.
Kelly
---------------------------------------------------------------------
This is certainly an interesting development (google dmarc email list).
I believe that yahoo has taken this (somewhat drastic) measure because
of the abuse their email servers have taken with regards to sending out
spam. I also believe that this is related to yahoo's account security
problems that have existed in recent years.
Personally, I've known more than a handful of people with yahoo email
accounts that were compromised. These account credentials were then used
to send out spam from the users accounts. My advice to them has been to
change the password immediately, along with any other accounts which
might have the same password. I also recommend that people choose some
another email service to use.
This action by yahoo brings up the matter of email lists and DMARC in
general.
As far as email lists go, I'm intending to deprecate ezmlm in favor of
mailman for use with QMT. Mailman is actively developed and maintained,
while ezmlm is not. Mailman is also far more robust than ezmlm, and
includes web based list management, for both list admins and users.
There has been a QMT wiki page for implementing mailman on QMT for some
time now, and now there's also a .qt mailman package in the new yum
repos for QMT. So for all you ezmlm users out there, be thinking about
migrating to mailman at some point. I expect we'll come up with a fairly
painless way to migrate once someone figures it out.
I don't have much to say regarding DMARC at this point. I'm expecting
that SPF and DKIM verification will be provided by spamdyke at some
point, so that's the plan for QMT. DKIM signatures for outbound messages
can be done with QMT, but it's not a 'stock' feature yet. There are
instructions here
http://wiki.qmailtoaster.com/index.php/How_to_Setup_DKIM_with_Qmail_Toaster
for setting it up. (I'm glad I looked that up - the code for it was in
an obscure place). If anyone is using this, please let us know. I'd like
to know how well it's working before I integrate it in the stock package.
One feature of DMARC I like is the ability to receive reports. This is
easy to set up, as it only entails an additional DNS record. IIRC, Dan
has tried this out and has received reports from Google. Any update on
this, Dan?
Thanks.
--
-Eric 'shubes'
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]