[HN Gopher] Show HN: DMARC Checker
___________________________________________________________________
Show HN: DMARC Checker
Author : awulf
Score : 17 points
Date : 2024-02-20 16:52 UTC (6 hours ago)
(HTM) web link (dmarcchecker.app)
(TXT) w3m dump (dmarcchecker.app)
| akshayKMR wrote:
| Hey, this comes at a perfect time for me.
|
| I had posted my app on Betalist about a week ago and received a
| vulnerability report about incorrectly configured DMARC from a
| security researcher. I made the fix but wasn't confident about
| it. Shortly after, I received a couple more similar emails.
|
| With this tool, my first check failed, citing an invalid SPF
| record. (I had an extra `.` at the end of my TXT record). Now,
| the check shows all passing.
|
| I hope all is good now (emails are wild).
|
| From my limited understanding: SPF <- Should
| this server be sending emails for this domain? DKIM <-
| Was this email tampered with? DMARC <- What should I, as
| a recipient, do if SPF or DKIM fails?
|
| Thanks!
| awulf wrote:
| I'm really happy to read that the app was able to help! Thanks
| for sharing.
| petecog wrote:
| I've given it a go.
|
| I recommend also https://mxtoolbox.com/dmarc.aspx
|
| I have no affiliation.
| petecog wrote:
| Great tool. Good comprehensive report. Keep up the great work.
| Hope it helps people.
|
| Email is such an amazing mess. Love and hate in equal measures
| bks wrote:
| Seems that this tool actually validates your email and checks
| its alignment vs. just checking to see if there is a dmarc
| record on the domain.
| RulerOf wrote:
| This is a really straightforward tool. Validating spf/dkim/dmarc
| by receiving an email strikes me as more effective than something
| that just looks at the DNS records. Thanks for sharing.
| aeadio wrote:
| A simple reject policy is showing up as an error, despite
| validating fine with other DMARC checker apps like MX Toolbox,
| The From domain (...) has an invalid DMARC record. ...
| DMARC record found: v=DMARC1; p=reject; The DMARC check
| result is permerror.
|
| No explanation as to what permerror means.
|
| It might also be useful if the tool attempted to circumvent DNS
| caching, so users can try tests in succession after updating.
| awulf wrote:
| There was a small bug in our DMARC record parser (it didn't
| like the semicolon at the end of the record). Sorry for that.
| Your DMARC record is definitely correct. The issue should be
| fixed now.
|
| Also, thanks for the idea about circumventing DNS caching. I'll
| look into adding that feature.
| jenoer wrote:
| I don't want to take away your spotlight, because it's a nice
| project you launched,
|
| But I do want to point out to people that
| https://github.com/domainaware/checkdmarc exists for quite a
| while. I use it often and have also integrated it in various
| automated tooling.
|
| (It also does not require handing out email addresses to
| strangers.)
| bks wrote:
| Also check out - https://appmaildev.com/en/dkim
| bks wrote:
| Great tool, one bit of feedback on the log report. Perhaps you
| can highlight the passing line in the SPF record, I have about
| 100 of these "The ip4 mechanism does not match." and then a lot
| of "The include mechanism matches and produces a pass result."
|
| Maybe you can highlight the passing statement? -
| https://app.screencast.com/Hu5ybB6K3fd9R
___________________________________________________________________
(page generated 2024-02-20 23:01 UTC)