[HN Gopher] Show HN: DMARC Checker
       ___________________________________________________________________
        
       Show HN: DMARC Checker
        
       Author : awulf
       Score  : 17 points
       Date   : 2024-02-20 16:52 UTC (6 hours ago)
        
 (HTM) web link (dmarcchecker.app)
 (TXT) w3m dump (dmarcchecker.app)
        
       | akshayKMR wrote:
       | Hey, this comes at a perfect time for me.
       | 
       | I had posted my app on Betalist about a week ago and received a
       | vulnerability report about incorrectly configured DMARC from a
       | security researcher. I made the fix but wasn't confident about
       | it. Shortly after, I received a couple more similar emails.
       | 
       | With this tool, my first check failed, citing an invalid SPF
       | record. (I had an extra `.` at the end of my TXT record). Now,
       | the check shows all passing.
       | 
       | I hope all is good now (emails are wild).
       | 
       | From my limited understanding:                   SPF <- Should
       | this server be sending emails for this domain?         DKIM <-
       | Was this email tampered with?         DMARC <- What should I, as
       | a recipient, do if SPF or DKIM fails?
       | 
       | Thanks!
        
         | awulf wrote:
         | I'm really happy to read that the app was able to help! Thanks
         | for sharing.
        
       | petecog wrote:
       | I've given it a go.
       | 
       | I recommend also https://mxtoolbox.com/dmarc.aspx
       | 
       | I have no affiliation.
        
         | petecog wrote:
         | Great tool. Good comprehensive report. Keep up the great work.
         | Hope it helps people.
         | 
         | Email is such an amazing mess. Love and hate in equal measures
        
         | bks wrote:
         | Seems that this tool actually validates your email and checks
         | its alignment vs. just checking to see if there is a dmarc
         | record on the domain.
        
       | RulerOf wrote:
       | This is a really straightforward tool. Validating spf/dkim/dmarc
       | by receiving an email strikes me as more effective than something
       | that just looks at the DNS records. Thanks for sharing.
        
       | aeadio wrote:
       | A simple reject policy is showing up as an error, despite
       | validating fine with other DMARC checker apps like MX Toolbox,
       | The From domain (...) has an invalid DMARC record.         ...
       | DMARC record found: v=DMARC1; p=reject;         The DMARC check
       | result is permerror.
       | 
       | No explanation as to what permerror means.
       | 
       | It might also be useful if the tool attempted to circumvent DNS
       | caching, so users can try tests in succession after updating.
        
         | awulf wrote:
         | There was a small bug in our DMARC record parser (it didn't
         | like the semicolon at the end of the record). Sorry for that.
         | Your DMARC record is definitely correct. The issue should be
         | fixed now.
         | 
         | Also, thanks for the idea about circumventing DNS caching. I'll
         | look into adding that feature.
        
       | jenoer wrote:
       | I don't want to take away your spotlight, because it's a nice
       | project you launched,
       | 
       | But I do want to point out to people that
       | https://github.com/domainaware/checkdmarc exists for quite a
       | while. I use it often and have also integrated it in various
       | automated tooling.
       | 
       | (It also does not require handing out email addresses to
       | strangers.)
        
       | bks wrote:
       | Also check out - https://appmaildev.com/en/dkim
        
       | bks wrote:
       | Great tool, one bit of feedback on the log report. Perhaps you
       | can highlight the passing line in the SPF record, I have about
       | 100 of these "The ip4 mechanism does not match." and then a lot
       | of "The include mechanism matches and produces a pass result."
       | 
       | Maybe you can highlight the passing statement? -
       | https://app.screencast.com/Hu5ybB6K3fd9R
        
       ___________________________________________________________________
       (page generated 2024-02-20 23:01 UTC)