Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Aggregate reports include wrong published domain #270

Open
dlucredativ opened this issue Nov 17, 2024 · 0 comments
Open

Aggregate reports include wrong published domain #270

dlucredativ opened this issue Nov 17, 2024 · 0 comments

Comments

@dlucredativ
Copy link

I have seen aggregate reports that I believe to originate from OpenDMARC (they have a boundary="report_section").

Those reports contain a feedback.policy_published.domain entry of the form subdomain.example.com, with example.com being the organizational domain. However, there is no DNS-Record _dmarc.subdomain.example.com, the reports are instead triggered by _dmarc.example.com.
According to RFC7489 appendix C, the domain field of PolicyPublishedType is

The domain at which the DMARC record was found

so the value should actually be example.com.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant