trusteddomainproject / OpenARC

Open source ARC implementation
BSD 2-Clause "Simplified" License
135 stars 45 forks source link

arc=fail (missing mandatory fields) #128

Closed gkohri closed 4 years ago

gkohri commented 4 years ago

Hi,

I'm testing a forwarding chain using an intermediary built with postfix, openDKIM, openDMARC, openARC and postsrsd.

In this test I sent an email from hotmail to the intermediary that then forwards the mail to Gmail. OpenARC is installed at the intermediary. Gmail says "dkim=pass", "spf=pass", but "arc=fail (missing mandatory fields)".

Here is the complete header:

Delivered-To: andy@gmail.com Received: by 2002:ac2:5f09:0:0:0:0:0 with SMTP id 9csp4171741lfq; Mon, 13 Jan 2020 05:39:38 -0800 (PST) X-Google-Smtp-Source: APXvYqyuuNJMo0D92k4w84DZYApcuU82A4Sp3ROOg6y2F6aOJv8Ft1VDYKMq1ULgzhqtjIgfeH4q X-Received: by 2002:a5e:a614:: with SMTP id q20mr11900098ioi.36.1578922778780; Mon, 13 Jan 2020 05:39:38 -0800 (PST) Return-Path: srs0=tv9s=3c=hotmail.com=andy@example.org Received: from nc1.example.org (nc1.example.org. [12.345.67.12]) by mx.google.com with ESMTPS id i189si12502452ioa.76.2020.01.13.05.39.38 for andy@gmail.com (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 13 Jan 2020 05:39:38 -0800 (PST) Received-SPF: pass (google.com: domain of srs0=tv9s=3c=hotmail.com=andy@example.org designates 12.345.67.12 as permitted sender) client-ip=12.345.67.12; Authentication-Results: mx.google.com; dkim=pass header.i=@hotmail.com header.s=selector1 header.b=YSz+76Ay; arc=fail (missing mandatory fields); spf=pass (google.com: domain of srs0=tv9s=3c=hotmail.com=andy@example.org designates 12.345.67.12 as permitted sender) smtp.mailfrom="srs0=tv9s=3c=hotmail.com=andy@example.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=hotmail.com Received: from localhost (localhost [127.0.0.1]) by nc1.example.org (Postfix) with ESMTP id 7B037E104F for gtest@example.org; Mon, 13 Jan 2020 13:39:21 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at example.org Authentication-Results: nc1.example.org (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com Received: from nc1.example.org ([127.0.0.1]) by localhost (nc1.example.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ulmbKz_ddy3X for gtest@example.org; Mon, 13 Jan 2020 13:39:20 +0000 (UTC) Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=40.92.40.64; helo=nam10-bn7-obe.outbound.protection.outlook.com; envelope-from=andy@hotmail.com; receiver= ARC-Seal: i=2; a=rsa-sha256; d=nc1.example.org; s=nc1-2020-1; t=1578922760; cv=fail; b=SnjN++js/Y4DE4+MWQZ9+Sgv/HYsTLwRYrndlD3YjeadgfrjF4ICdVjdWBl77O/NRdba3uKsOqnHQGvaDu7AHlpPJVO+5rZLAcpUOc/lvRFFaIndjEfLNnMdvo2wqZQBVw++d/5BcWA6FOPPdmU4RZxOIZ0PbRhZqJfG2o7/UuU= ARC-Message-Signature: i=2; a=rsa-sha256; d=nc1.example.org; s=nc1-2020-1; t=1578922760; c=relaxed/relaxed; bh=dd5nRVy7oVP60fOs8wmKDoqQOkGHFOZnHNl1dtLlk3U=; h=Received-SPF:DKIM-Filter:ARC-Message-Signature: ARC-Authentication-Results:DKIM-Signature:Received:Received: Received:From:To:Subject:Thread-Topic:Thread-Index:Date:Message-ID: Accept-Language:Content-Language:X-MS-Has-Attach: X-MS-TNEF-Correlator:x-incomingtopheadermarker:x-tmn: x-ms-publictraffictype:x-incomingheadercount: x-eopattributedmessage:x-ms-office365-filtering-correlation-id: x-ms-traffictypediagnostic:x-microsoft-antispam: x-microsoft-antispam-message-info:x-ms-exchange-transport-forked: Content-Type:MIME-Version:X-OriginatorOrg: X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: X-MS-Exchange-CrossTenant-Network-Message-Id: X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: X-MS-Exchange-CrossTenant-originalarrivaltime: X-MS-Exchange-CrossTenant-fromentityheader: X-MS-Exchange-CrossTenant-id: X-MS-Exchange-Transport-CrossTen ARC-Authentication-Results: i=2; nc1.example.org; dmarc=pass (p=none dis=none) header.from=hotmail.com; dkim=pass (2048-bit key; unprotected) header.d=hotmail.com header.i=@hotmail.com header.b=YSz+76Ay; dkim-atps=neutral DKIM-Filter: OpenDKIM Filter v2.11.0 nc1.example.org 1B185E104E Received: from NAM10-BN7-obe.outbound.protection.outlook.com (mail-bn7nam10olkn2064.outbound.protection.outlook.com [40.92.40.64]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by nc1.example.org (Postfix) with ESMTPS id 1B185E104E for gtest@example.org; Mon, 13 Jan 2020 13:39:19 +0000 (UTC) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=NgcFkCHJg1w9chlh8mVe+613NOq/JoTj2U0DZ93zm/sJ4/ErsG6G6IFIgeJVph3o7qiTt5gKw/68+r62LX2oOwLVCEO5cWJpu/e06JKYHmqnTZNm5Ceb1OBnXMDs9PkzDo0LywwI/J78yc3qaaADXn/912tiX1ChgN1A2WmlYfKNpT8IUVSbj2O86+5BR8XqR85kZ0bmzwMeHw+n2KjVIAHtYTlbWlrLTqMGC7Gc22zbXl1RuDJy8UPOwhn3DgCgvN+JBMe17Pab2o+zI62p03vRbjk54czYcXUeJ7SeaPr5TqwVhF32nXOvUJ1y+vSEpmGJKoEK15N2crEz3dwN8A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=dd5nRVy7oVP60fOs8wmKDoqQOkGHFOZnHNl1dtLlk3U=; b=N8vCNAAzJo1ZMpuDAiWCFsEvHhReOZe8MD/I80KqUDwmLmzhw7PGsCNdw6aEBJDNtLtJoo30pxNLZXLkdT4egXQA2bkJ7wI8C/SK7gyltWBzBSZlXro2d4MAKavMLQzEOXcOz23CBdv0b2B9DKHMJfi6BRQpZVlbCKjH77Gfz4v/ScZOKRBqhIXqSaadDKqb+8Z3qYJdFmvs0s6pQHrcMYHdsdhc4gigdfJqgTB8YILr9+6Q5lob8p2Qagrt6+gfLBF5zHNQVrG0KzMm7aH9qm/dikMt3hgzEp9j0lC9FuNjnFloOuVpg5S3VyCZ/SZf2aHDd2TUF9SL37b0zlxpyQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=dd5nRVy7oVP60fOs8wmKDoqQOkGHFOZnHNl1dtLlk3U=; b=YSz+76Ayp9Q88WLEZxE2DzUEaQFFsTiyxUdlb99dqPKb/T8E42OLczSHDyrwcuZSgMJvQuh6aE0lhVxrxG2Iqu44SeyqWGj/tY+YdPrypqnS3gN4EoYQrrHkZQLoRyDOssrT8To5osnsEnjBl1rSwnTNrSQ59jKsoCUGhbxGttLD/h6voXgEO7bw9hkcgM75GSuJRd1Y1+XfSdj3HaeUSgsd3hEJPttzqlYRgOBl9UvTV0xMxmbSoy9RWTJkB4qkpujOCBWpRJ2QAPLXTTEYdGYilhx5BPGJ6i0e20nESvI/AteffoGq7eYyhhslcAKOxOjaxllMotM1exHlQJ9McQ== Received: from BN7NAM10FT017.eop-nam10.prod.protection.outlook.com (10.13.156.56) by BN7NAM10HT176.eop-nam10.prod.protection.outlook.com (10.13.156.254) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2623.9; Mon, 13 Jan 2020 13:39:18 +0000 Received: from MN2PR18MB2896.namprd18.prod.outlook.com (10.13.156.55) by BN7NAM10FT017.mail.protection.outlook.com (10.13.156.62) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2623.9 via Frontend Transport; Mon, 13 Jan 2020 13:39:18 +0000 Received: from MN2PR18MB2896.namprd18.prod.outlook.com ([fe80::fdbb:a924:8f61:82d0]) by MN2PR18MB2896.namprd18.prod.outlook.com ([fe80::fdbb:a924:8f61:82d0%3]) with mapi id 15.20.2623.015; Mon, 13 Jan 2020 13:39:18 +0000 From: Andy. andy@hotmail.com To: "gtest@example.org" gtest@example.org Subject: Full stack: SPF, DKIM, SRS, DMARC, ARC Thread-Topic: Full stack: SPF, DKIM, SRS, DMARC, ARC Thread-Index: AQHVyhbFPabN79sGQkWtq9YwuqWu1A== Date: Mon, 13 Jan 2020 13:39:18 +0000 Message-ID: MN2PR18MB2896782678B6316BD8884998D6350@MN2PR18MB2896.namprd18.prod.outlook.com Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-incomingtopheadermarker: OriginalChecksum:28494CEA63776A927F21F9DFD9F775A8DA1796473D4ED7E8FD0544AE8CB7F42F;UpperCasedChecksum:7A2439A354B1477899A48A27AD14FC226607F95EB2E6A564BBF813ECBF5CD1BB;SizeAsReceived:6653;Count:42 x-tmn: [/nWd4drjCaTE77PKp7vfuXsE+01EREUR] x-ms-publictraffictype: Email x-incomingheadercount: 42 x-eopattributedmessage: 0 x-ms-office365-filtering-correlation-id: 03459bea-7b6f-4936-7d3b-08d7982dfd72 x-ms-traffictypediagnostic: BN7NAM10HT176: x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: lfIwj/SsedEvStBR0Lpt0Zb3nK5Dv11Nnz+syU/OA64JGI9tRiXgNwJq8ll/fkPEhoPIY6v53VJGSQFVhhXjXCAAqIxO/fArE08CnF+WgD/hqHFpQd6LUovdc2enYM9wlbwMtb7X6+GtPP1bDBqHHxSYBkIxWgth+AUXW/3RuFr/xSN0IHx0JXpsKCO7ujh9 x-ms-exchange-transport-forked: True Content-Type: multipart/alternative; boundary="_000MN2PR18MB2896782678B6316BD8884998D6350MN2PR18MB2896namp" MIME-Version: 1.0 X-OriginatorOrg: hotmail.com X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-Network-Message-Id: 03459bea-7b6f-4936-7d3b-08d7982dfd72 X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Jan 2020 13:39:18.8234 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Internet X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN7NAM10HT176