Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance DMARC for campus email
Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance What is DMARC? An email standard that allows email providers to to verify that email was sent from a valid email address. Case 1: Email from bucky.badger@wisc.edu to sparty@gmail.com Gmail asks WiscMail servers, “Is this email legitimate?” WiscMail servers, “Yes, that is legitimate. Bucky rocks!” Gmail delivers mail to sparty@gmail.com
Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance How does DMARC work? Email systems “talk” to each other using the DMARC standard to verify email senders are legitimate. Case 2: Email from sparty@msu.edu to bucky.badger@wisc.edu WiscMail servers ask MSU servers, “Is this email legitimate?” MSU, “Nope! We don’t know who that is!” WiscMail potential actions include: deliver block quarantine discard
Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance Who is impacted by this change? Any system “spoofing” or impersonating a UW Madison email addresses UW-Madison users who send email messages thru 3rd- party mass email providers (e.g. MailChimp, Constant Contact, etc.) using an @wisc.edu email address as the “From” address.* Non-UW-Madison email accounts which send as an @wisc.edu email address (e.g. Gmail account configured to send as an @wisc.edu address). Third-party email scripts/servers that don’t send email using on-campus mail services which are sending “FROM” a wisc.edu email address. * Can be configured to send DMARC compliant email
Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance Who is not impacted by this change? UW-Madison Office 365 web client, desktop app, and mobile app Individuals sending outbound email Office 365 add-ons for mail-merge functionality Systems which are able to authorize end-users’ use of their own email address within the system List servers configured to work with DMARC* UW-Madison email lists Google Groups UW-Madison campus SMTP Relay service *Departmental and off-campus list servers need to be updated to support DMARC
Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance How does this impact UW Madison inbound/outbound email messages? Inbound Inbound messages (from any source other than the UW- Madison Office 365 tenant) which spoof an @wisc.edu email address will be flagged as SPAM. These messages will either be rejected by the email system, quarantined, or delivered to the intended recipient’s SPAM email folder. Outbound Recipient email systems (e.g. Gmail, etc.) will reject or quarantine email messages which spoof an @wisc.edu email address.
Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance What can you do to ensure you are compliant with DMARC standards? Faculty/Staff/Students No changes necessary unless they are sending messages from a non-UW email service which is “spoofing” an @wisc.edu email address. Email Domain/Application/System Admins See the DMARC Website for more information on how to achieve DMARC compliance. Contact 3rd-Party email providers to determine if they are capable of DMARC compliance. If you manage a system which sends email through a mechanism other than UW Madison mail relay, contact the ECC Team for a consultation.
Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance What is the timeline? Current and Ongoing Execute communication plan Develop domain policies with Hostmaster Convert campus relayers Fall/Winter 2018 Tag subjects of inbound mail violating DMARC standard Publish SPF ~all for wisc.edu (following conclusion of Spring semester) Spring/Summer 2019 (Tentative) Publish 1% DMARC record for wisc.edu Fall 2019 (Tentative) Publish DMARC record for wisc.edu
Domain-based Authentication, Reporting, and Conformance DMARC Domain-based Authentication, Reporting, and Conformance Questions?