DMARC Monitoring Badsender.com - Summer 2021

After a hectic summer with no downtime, I share our data with you today DMARC for the month of July & August 2021!

To summarize: Today, our security policy is at "quarantine", which means that any email with SPF & DKIM authentication failures will be delivered as junk mail to any organization (ISP, Webmails, companies, ...) able to interpret and apply the DMARC security rule.

Ultimately, we have two goals for 2021:

  1. Change our security policy from "quarantine" to "reject": we would then ask all ISPs/Webmails/Filters (interpreting DMARC) to reject emails with bad SPF & DKIM authentication.
  2. Legitimize all our email flows (and yes, we use several distinct tools for each type of sending - understand, we don't have all our eggs in the same basket :p).
  3. Apply a "strict" SPF & DKIM alignment instead of a "relaxed" one: We're plugging EVERYTHING into Badsender.com!

This 3rd point is too complicated to set up (cf. point n°2), we will remain in "relaxed" since all our legitimate flows will be branded with a sub-domain of Badsender.com. And if one day things change... We will study a passage towards a strict alignment!

We are aware that it will take time and energy but it is not impossible! And if it allows us to reduce the risks of using our domain name, it's worth it.

Let's get to the heart of the matter... Enjoy your reading 🙂

July-August 2021 compliance rate

To be DMARC compliant, the email must return a properly authenticated and properly aligned (soft or hard) SPF or DKIM record.

Here are our results during the summer of 2021 (I voluntarily keep the history since the first DMARC monitoring was published to compare the evolution of the data):

Badsender.comVolumesCompliantNon-CompliantNot Authenticated
August 20211 71199,8%0,1%0,1%
July 20212 12482,6%5,6%11,8%
June 20214 71799,6%0,2%0,2%
May 20213 90099,7%0,1%0,2%
April 20214 21499,4%0,1%0,5%
March 20213 54999,1%0,9%0,0%
February 20215 22199,8%0,2%0,0%
January 20214 84398,0%1,9%0,1%
Our compliance rate for the year 2021

You can see that in July, our compliance rate was below 90%, due to a small spam wave. On the other hand, we found a "normal" rate (almost 100%) in August! Spammers never take a vacation 🙂

Authentication & SPF & DKIM alignment

For an email to be properly authenticated with SPF, the IP used must be declared in the SPF record of the email envelope domain (understand here the MailFrom/Return-path domain - visible in the SMTP header of an email).

SPF authentication rate for badsender.com in 2021 - DMARC monitoring
SPF authentication rate for badsender.com in 2021

You'll notice that July was a hectic month... This is the first time our SPF authentication rate has fallen below 90%! And it's not our fault this time 🙂

And for an e-mail to be correctly aligned with SPF, the domain of the e-mail envelope (here the MailFrom/Return-path) must be identical or from a sub-domain of the FROM domain (cf. domain of the sending address).

SPF alignment rate for badsender.com in 2021 - DMARC monitoring
SPF alignment rate for badsender.com in 2021

Some flows show an alignment problem but do not deserve any intervention from us. On the other hand, some flows still need to be optimized on our side so that SPF is fully aligned with DMARC.

For an email to be properly authenticated with DKIM, the email will need to have a valid DKIM signature (regardless of the domain used in the "d=" statement).

DKIM authentication rate for badsender.com in 2021 - DMARC monitoring
DKIM authentication rate for badsender.com in 2021

With the spam wave in July, our DKIM authentication rate was down. We found an almost perfect rate in August!

Need help?

Reading content isn't everything. The best way is to talk to us.


As far as DKIM alignment is concerned, for an e-mail to be correctly aligned, the domain declared in the DKIM signature (contained in the "d=") must be identical to or come from the sub-domain of the FROM domain (cf. domain of the sending address).

DKIM alignment rate for badsender.com in 2021
Our DKIM alignment rate for the year 2021

Like SPF alignment, some flows show authentication problems but do not deserve any intervention from us. On the other hand, some flows still need to be optimized on our side so that DKIM is also fully aligned with DMARC.

The last DKIM-related rate is the rate of unsigned e-mails (and yes, there are still some). These are emails that have no DKIM signature.

Our unsigned email rate with DKIM for the year 2021

You will notice that in July our rate of unsigned emails has exploded... This is exclusively due to this famous spam wave!

Distribution of non-compliant & non-authenticated emails

Here is the list of "Sender rDNS" (understand here the domain name that is associated with an IP) reported as "non-compliant" on June 2021:

OrganizationSender rDNSCategoryVolumesPercentageSourceAction
USA.net*.mx.netWebmail11493.4%UnknownNo action
Microsoft*.outlook.comWebmail21.7%UnknownNo action
Google*.google.comWebmail21.7%UnknownNo action
Sharpspring*.marketingautomation.servicesESP10.8%KnownMake it compliant
Verizon Media*.yahoo.comWebmail10.8%UnknownNo action
CCM Benchmark*.benchmark.frESP10.8%UnknownNo action
CCM Benchmark*.ccmbg.comESP10.8%UnknownNo action
Non-compliant" sources between July and August 2021

We have had a lot of non-compliant feedback from the rDNS sender "mx.net". Only Sharpspring's flow should be compliant (so will have to study and correct it).

And the list of "Sender rDNS" returned as "unauthenticated":

OrganizationSender rDNSCategoryVolumesPercentageSourceAction
USA.net*.mx.netWebmail24798.4%UnknownNo action
Microsoft*.outlook.comWebmail20.8%UnknownNo action
UnknownUnknown20.8%UnknownNo action
Non-authenticated" sources between July and August 2021

The same goes for the "non-authenticated" flows... We have had a lot of feedback from the rDNS sender "mx.net". However, none of the flows need to be studied and corrected.

SPF & DKIM error trends

We have the possibility to know on each "Sender rDNS" what are the problems we have encountered and that will be corrected.

Below are the reported trends on SPF & DKIM errors for the month of June 2021:

Trend of the most frequent SPF errors

SPF failure trend for July & August 2021
SPF failure trend for July & August 2021

During the summer, 417 emails report an SPF alignment issue, 71 emails report SPF failure and 263 emails report an SPF authentication issue.

Trend of the most frequent DKIM errors

DKIM failure trend for July & August 2021
DKIM failure trend for July & August 2021

On the DKIM error side, 365 emails report a DKIM authentication issue, 75 emails report a DKIM alignment issue, 39 emails report DKIM failure and 2 emails report a permanent error.

Our roadmap for this September!

For the beginning of the school year, the objectives have not really changed compared to this summer:

  1. Finish our infrastructure migration.
  2. Correct the flows to be DMARC compliant.
  3. Upgrade our DMARC security policy to "quarantine" asap.

Conclusion

After a summer not really of any rest, we will be able to take again our conformity DMARC and seriously look at the flows that need to be fixed. Although before that, we already have to finalize our infrastructure migration (which is taking longer than expected).

Our other content related to DMARC (from near or far) :

Support the "Email Expiration Date" initiative

Brevo and Cofidis financially support the project. Join the movement and together, let's make the email industry take responsibility for the climate emergency.

Share
The author

Laisser un commentaire

Your email address will not be published. Les champs obligatoires sont indiqués avec *