
From nobody Tue Jan 23 17:01:28 2018
Return-Path: <johnl@taugh.com>
X-Original-To: ima@ietfa.amsl.com
Delivered-To: ima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B154812D88E for <ima@ietfa.amsl.com>; Tue, 23 Jan 2018 17:01:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1536-bit key) header.d=iecc.com header.b=6a8grSGN; dkim=pass (1536-bit key) header.d=taugh.com header.b=YOK8hWnP
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ew5-PdoL5E_F for <ima@ietfa.amsl.com>; Tue, 23 Jan 2018 17:01:25 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ECD1D127698 for <ima@ietf.org>; Tue, 23 Jan 2018 17:01:24 -0800 (PST)
Received: (qmail 44120 invoked from network); 24 Jan 2018 01:01:24 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:subject:mime-version:content-type:user-agent; s=ac55.5a67dae4.k1801; bh=vi3OW0MLPTgiaD0oEulRnzTnVLWnYVGk7Yhc6I4C+cM=; b=6a8grSGNf1oeQCrFE8HVnHiyE0236pBjZ6lHgN9ZRgJqkKyLPbK2sS3msF2UObICD0vTSQRujxrj2rd06N1V0Xj3eKSHA2Ygmvfdpj2JALCXDIQJ8BzoDALKJvjTy/nGsl/4pZJzuoU2JmGfGXqI87zv5D28hXnkCju/T7eRWBK1eRSBjkvYU0WdlkCmIdmSZ0OGxh9pZnQ7NpmdnOBfUxdjWdgzxo2cFxSCMvOsc9V8kfnKzIlx9y4O/sChrIdc
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:subject:mime-version:content-type:user-agent; s=ac55.5a67dae4.k1801; bh=vi3OW0MLPTgiaD0oEulRnzTnVLWnYVGk7Yhc6I4C+cM=; b=YOK8hWnPvlvcxYN0NLLnYrYtqm/iPLUI0+5nRf8SwpweEsxe2HszqksCnl88gA7OxIJJmn077qZ8slecAMRVhiy4MopLHbp/xUyAjxbpQA/7jdomIedEmqBkK7Lou9/906RDezBEWDo1cgTn1aqVLf6Y1TTQL6OpSP0I3SpKFH9MTOgZxFPeWND97pEpfHpOdWAjXgZUm+OwEbBTVUe0k/vqwG6sHsXHA6Vt9uExKRzIF4fzrEykWIfW3lrRdH82
Received: from localhost ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.2/X.509/AEAD) via TCP6; 24 Jan 2018 01:01:23 -0000
Date: 23 Jan 2018 20:01:23 -0500
Message-ID: <alpine.OSX.2.21.1801232001100.22978@ary.qy>
From: "John R Levine" <johnl@taugh.com>
To: ima@ietf.org
User-Agent: Alpine 2.21 (OSX 202 2017-01-01)
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII; format=flowed
Archived-At: <https://mailarchive.ietf.org/arch/msg/ima/qNMLp0aUUYGjONcNxYN21o6jcWE>
Subject: [EAI] New version of E-mail Authentication for Internationalized Mail draft
X-BeenThere: ima@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "EAI \(Email Address Internationalization\)" <ima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ima>, <mailto:ima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ima/>
List-Post: <mailto:ima@ietf.org>
List-Help: <mailto:ima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ima>, <mailto:ima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jan 2018 01:01:27 -0000

Read all about it: 
https://datatracker.ietf.org/doc/draft-levine-appsarea-eaiauth/

This is an updated version of a draft I wrote two years ago, that tries to nail 
down the small changes to SPF, DKIM, and DMARC in EAI messages.  This version 
adds a section for the Authentication-Results header.

What it mostly says is that wherever you can have a domain name in a mail 
message header it can be a U-label, and wherever there's a mailbox, the local 
part can be UTF-8, while stuff in the DNS doesn't change and domains there are 
A-labels, same as always.  It's intended to be utterly unsurprising, but 
there's enough ambiguity and well-intended bad advice in existing RFCs that I 
think this is worth doing.

I'm working on an intro to implenting EAI document underwritten by ICANN so it 
would be nice if this were far enough along that I could point to it in the 
relevant sections rather than just Making Stuff Up.

R's,
John


From nobody Wed Jan 24 02:07:54 2018
Return-Path: <hmdmhdfmhdjmzdtjmzdtzktdkztdjz@gmail.com>
X-Original-To: ima@ietfa.amsl.com
Delivered-To: ima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CAF3112DA0D for <ima@ietfa.amsl.com>; Wed, 24 Jan 2018 02:07:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.2
X-Spam-Level: 
X-Spam-Status: No, score=-2.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FROM_LOCAL_NOVOWEL=0.5, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Yk8xCE-VvT_t for <ima@ietfa.amsl.com>; Wed, 24 Jan 2018 02:07:50 -0800 (PST)
Received: from mail-vk0-x22a.google.com (mail-vk0-x22a.google.com [IPv6:2607:f8b0:400c:c05::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E1ECB12D964 for <ima@ietf.org>; Wed, 24 Jan 2018 02:07:49 -0800 (PST)
Received: by mail-vk0-x22a.google.com with SMTP id w201so2187447vkw.0 for <ima@ietf.org>; Wed, 24 Jan 2018 02:07:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=d4vvA4ugh2rT89ojE56DA8n+7fmogS5Q2an/+LqNsQY=; b=c0DJUwvtlVtcY0ljJyTsDZLVyBVfvnpAF1sjy/ptyWdp/GPja9fszB8oCEMwnxkKLu LiU3r717XtQKzjdY7GDZ3IjB9PJ2alvT9XXY2zvu5ninGdNBCFEPdxPafu4ieLw4W5Kt ygBxIIQyP7v8/rYaJ9nrN2PnS/8Gl9rzGcF29hisHVl3HXFjJFGTEXIYRk2WayN/aUKs 9jIrN/xolvN92wa3uFZZ5mEeJSkaX1tyOzVg0KVkYB8R1IssYKJQhbYECM8NlwTxXYud rsXymhpvYglhsv6ou3GX/VAFHbqCY5HWwRk0QltiqmbdsA7pr8n0Blx/oQRJUwkAAHxN +P4w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=d4vvA4ugh2rT89ojE56DA8n+7fmogS5Q2an/+LqNsQY=; b=RqHRg4J+4C2fVU1WS36yaU/FMoSQzvILY+LXSLtoD+0CVRBslmU/4XhQ7Xq/m37cUe 5iPF8Z3UujRUf/b8S0C/MYVr74morO2d6fNnsO9e6rzf4bw9mkBFpEyPM0+QBfTKY3em 08dRs8NvRr8rOSvpaXjwt6GPybpayWBZNnt3kUflZJ8Dr5Pngi/YZ9/F57RGIB2wuh2X AMG+xu1Hh23IWizh2uFpSJ4RhTETa8JS78gjXdTtTChfPynKMyVYbsXoM9LbU8bAK4/r jgvGRmTdgOMiHvAQ+qyq0DG/ElGikDwl71R62cJ3HMJSXQjcbz61gBw69wy/WgLhEYtG sovA==
X-Gm-Message-State: AKwxytfXoAgS2l4I4BjKROiZvGkTna6uYpMgUNAmQq5iIowDKKBOm1OD fSRuKgsS+9NX0SzxVPKsYCajlVKGGX5d5XGEeX1+tB2F0w==
X-Google-Smtp-Source: AH8x224eHdKaarBEUeeksT5LLgTAIGZ0T6k8c8ZXcYQEhX1B23OW8V+Q6VskkwucmNTnRPATJjSIIQoF8DNCVRmvaaw=
X-Received: by 10.31.188.72 with SMTP id m69mr3826061vkf.86.1516788468940; Wed, 24 Jan 2018 02:07:48 -0800 (PST)
MIME-Version: 1.0
Received: by 10.176.10.27 with HTTP; Wed, 24 Jan 2018 02:07:08 -0800 (PST)
In-Reply-To: <alpine.OSX.2.21.1801232001100.22978@ary.qy>
References: <alpine.OSX.2.21.1801232001100.22978@ary.qy>
From: Frank Ellermann <hmdmhdfmhdjmzdtjmzdtzktdkztdjz@gmail.com>
Date: Wed, 24 Jan 2018 11:07:08 +0100
Message-ID: <CAHhFyboKJiDipz1XaCmGCiHpQBOa8cHZUfgXUBADdOTK6OPTpQ@mail.gmail.com>
To: John R Levine <johnl@taugh.com>
Cc: IETF EAI <ima@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ima/wSX44JMJ2GqZH4n4r_v-5wpRy4w>
Subject: Re: [EAI] New version of E-mail Authentication for Internationalized Mail draft
X-BeenThere: ima@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "EAI \(Email Address Internationalization\)" <ima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ima>, <mailto:ima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ima/>
List-Post: <mailto:ima@ietf.org>
List-Help: <mailto:ima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ima>, <mailto:ima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jan 2018 10:07:53 -0000

Hi, I've certainly forgotten what I put in draft-ellermann-spf-eai-05
more than 6 years ago,
but apparently I thought that local part macros might not work as
expected (bad enough
to mention this also in the security considerations). At this time EAI
and SPF were still
experimental, and RFC 7208 was still Scott's draft. :-)

Unrelated Gmail observation, they tag SPF PASS + DKIM PASS + DMARC FAIL as spam.

On 24 January 2018 at 02:01, John R Levine <johnl@taugh.com> wrote:
> Read all about it:
> https://datatracker.ietf.org/doc/draft-levine-appsarea-eaiauth/
>
> This is an updated version of a draft I wrote two years ago, that tries to
> nail down the small changes to SPF, DKIM, and DMARC in EAI messages.  This
> version adds a section for the Authentication-Results header.
>
> What it mostly says is that wherever you can have a domain name in a mail
> message header it can be a U-label, and wherever there's a mailbox, the
> local part can be UTF-8, while stuff in the DNS doesn't change and domains
> there are A-labels, same as always.  It's intended to be utterly
> unsurprising, but there's enough ambiguity and well-intended bad advice in
> existing RFCs that I think this is worth doing.
>
> I'm working on an intro to implenting EAI document underwritten by ICANN so
> it would be nice if this were far enough along that I could point to it in
> the relevant sections rather than just Making Stuff Up.
>
> R's,
> John
>
> _______________________________________________
> IMA mailing list
> IMA@ietf.org
> https://www.ietf.org/mailman/listinfo/ima


From nobody Wed Jan 24 06:42:47 2018
Return-Path: <johnl@taugh.com>
X-Original-To: ima@ietfa.amsl.com
Delivered-To: ima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 447E1124D68 for <ima@ietfa.amsl.com>; Wed, 24 Jan 2018 06:42:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1536-bit key) header.d=iecc.com header.b=4bj/rKAT; dkim=pass (1536-bit key) header.d=taugh.com header.b=zBZic0kV
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YT4z8dQohFVh for <ima@ietfa.amsl.com>; Wed, 24 Jan 2018 06:42:43 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2BFE7124BAC for <ima@ietf.org>; Wed, 24 Jan 2018 06:42:43 -0800 (PST)
Received: (qmail 74800 invoked from network); 24 Jan 2018 14:42:41 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:user-agent; s=1242e.5a689b61.k1801; bh=/5R3JUCbtEWx+2q19JxJMPaSW3zwF9W76o1+2/hUYiw=; b=4bj/rKAToJwpfs2cXZmVLQ1QSzex2PAsDzEkjkcEKuktR9jqXy6qJjtfE865Y2XAeIVdHpnhoV2+mb5UWh0PxTzd1n6PZIajA88Zy8ZKeVMLHvce3MO0dN1y9rNtMmlLoABZdc8CwgwFjsSqBLz96MjNcw1ka7tswhNlpw5aDZ3b6YBWcE3YekMvp0AjN3JMhVpjyOSl5o9PUYqdfqa/cI/yIxXJZgfE51Rps6FcpVf0g/EE6T5/djke5vgO1jLZ
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:user-agent; s=1242e.5a689b61.k1801; bh=/5R3JUCbtEWx+2q19JxJMPaSW3zwF9W76o1+2/hUYiw=; b=zBZic0kVJ25ImSbtYGaVlMFryUGmMPNvbL2hocP/0IncUHbs3RDZS8L4L1QNExVxIcKuAjEUWc0GLUB/3ZK0hQ9Qcf100MXU9oiWpFE15bbez5lWVTOabqlbDTpiBVI29vaIeOb7yfjdYYpsxKLgzkZd8i9dpcY+P9S/o24boe0Ct0gEspMahxFLhlSJIZCfMr6EFg3+lmN8iHxvSH/XGK1qNQq4XfEsCpdA8J4z17xCilq6hbHrYTn2i9o3TqSA
Received: from localhost ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.2/X.509/AEAD) via TCP6; 24 Jan 2018 14:42:41 -0000
Date: 24 Jan 2018 09:42:42 -0500
Message-ID: <alpine.OSX.2.21.1801240939330.23908@ary.qy>
From: "John R Levine" <johnl@taugh.com>
To: "Frank Ellermann" <hmdmhdfmhdjmzdtjmzdtzktdkztdjz@gmail.com>
Cc: "IETF EAI" <ima@ietf.org>
In-Reply-To: <CAHhFyboKJiDipz1XaCmGCiHpQBOa8cHZUfgXUBADdOTK6OPTpQ@mail.gmail.com>
References: <alpine.OSX.2.21.1801232001100.22978@ary.qy> <CAHhFyboKJiDipz1XaCmGCiHpQBOa8cHZUfgXUBADdOTK6OPTpQ@mail.gmail.com>
User-Agent: Alpine 2.21 (OSX 202 2017-01-01)
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII; format=flowed
Archived-At: <https://mailarchive.ietf.org/arch/msg/ima/yY6TeDIlAU2TSi_PiEeq_8UD0AI>
Subject: Re: [EAI] New version of E-mail Authentication for Internationalized Mail draft
X-BeenThere: ima@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "EAI \(Email Address Internationalization\)" <ima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ima>, <mailto:ima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ima/>
List-Post: <mailto:ima@ietf.org>
List-Help: <mailto:ima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ima>, <mailto:ima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jan 2018 14:42:45 -0000

> but apparently I thought that local part macros might not work as
> expected (bad enough

Scott mentioned that on another list.  My first suggestion is to say that 
macros that use local parts don't work with EAI addresses, the second is 
to say that you use the UTF-8 local parts as is and if that creates some 
hard to type DNS names, so be it.  (The DNS is 8 bit clean other than 
ASCII case folding so there's no DNS problems.)

It has always been my impression that SPF local parts are fragile even 
with ASCII names, e.g., what DNS name does this entirely valid ASCII local 
part turn into?

    a.b\.c\\d)e

Regards,
John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
Please consider the environment before reading this e-mail. https://jl.ly

