Opened 19 months ago

Closed 16 months ago

Last modified 9 months ago

#81 closed enhancement (wontfix)

BCP: Do I send reports to any domain that requests them?

Reported by: fosterd@… Owned by: alex_brotman@…
Priority: minor Milestone:
Component: dmarc-aggregate-reporting Version:
Severity: - Keywords:


Spammers could use DMARC reports to monitor the effectiveness of their campaigns, and we do not want to help them. Do existing implementations send reports to any domain that requests them, or only to those domains that are considered "acceptable"? If reports are only sent to acceptable domains, what sort of criteria have been useful?

System administrators will appreciate such advice. Product developers will need guidance about the features they should provide so that a system administrator can control which domains do not receive reports.

Change History (3)

comment:1 Changed 16 months ago by alex_brotman@…

  • Owner set to alex_brotman@…
  • Status changed from new to assigned

comment:2 Changed 16 months ago by alex_brotman@…

  • Resolution set to wontfix
  • Status changed from assigned to closed

List consensus suggests that there's no true risk here, closing as suggested.

comment:3 Changed 9 months ago by alex_brotman@…

  • Component changed from dmarc-bis to dmarc-aggregate-reporting
Note: See TracTickets for help on using tickets.