Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

FORTRAN is the language of Powerful Computers. -- Steven Feiner


computers / alt.privacy.anon-server / Re: NYM ACCOUNT AND MAIL SERVER

SubjectAuthor
* NYM ACCOUNT AND MAIL SERVERNomen Nescio
+* Re: NYM ACCOUNT AND MAIL SERVERGrant Taylor
|`* Re: NYM ACCOUNT AND MAIL SERVERNomen Nescio
| +- Re: NYM ACCOUNT AND MAIL SERVERYamn Remailer
| `* Re: NYM ACCOUNT AND MAIL SERVERGrant Taylor
|  `- Re: NYM ACCOUNT AND MAIL SERVERNomen Nescio
`- Re: NYM ACCOUNT AND MAIL SERVERNomen Nescio

1
NYM ACCOUNT AND MAIL SERVER

<3eefa36bac194cfdc279ec566f4a2f95@dizum.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=17977&group=alt.privacy.anon-server#17977

  copy link   Newsgroups: alt.privacy.anon-server
From: nobody@dizum.com (Nomen Nescio)
Subject: NYM ACCOUNT AND MAIL SERVER
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-15"; format=flowed
Content-Transfer-Encoding: 8bit
Message-ID: <3eefa36bac194cfdc279ec566f4a2f95@dizum.com>
Date: Sun, 28 Apr 2024 15:38:45 +0200 (CEST)
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!news2.arglkargh.de!alphared!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Nomen Nescio - Sun, 28 Apr 2024 13:38 UTC

Usually my nyms works well.
When sending mail, there are few recipients that I can not to reach.
I receive an error message "Mail delivery failed"

SMTP error from remote mail server after end of data:
host eur.olc.protection.outlook.com [104.47.17.97]:
550 5.7.509 Access denied, sending domain [NYMPH.PARANOICI.ORG] does
not pass DMARC verification and has a DMARC policy of reject.

There is a way to avoid this?

Re: NYM ACCOUNT AND MAIL SERVER

<v0mtjq$t7l$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=17981&group=alt.privacy.anon-server#17981

  copy link   Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.omega.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: alt.privacy.anon-server
Subject: Re: NYM ACCOUNT AND MAIL SERVER
Date: Sun, 28 Apr 2024 20:36:58 -0500
Organization: TNet Consulting
Message-ID: <v0mtjq$t7l$1@tncsrv09.home.tnetconsulting.net>
References: <3eefa36bac194cfdc279ec566f4a2f95@dizum.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 29 Apr 2024 01:36:58 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="omega.home.tnetconsulting.net:198.18.1.140";
logging-data="29941"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla Thunderbird
Content-Language: en-US
In-Reply-To: <3eefa36bac194cfdc279ec566f4a2f95@dizum.com>
 by: Grant Taylor - Mon, 29 Apr 2024 01:36 UTC

On 4/28/24 08:38, Nomen Nescio wrote:
> When sending mail, there are few recipients that I can not to reach.

Are those recipients hosted with protection.outlook.com? Or are those
recipients hosted elsewhere and forwarding to something else hosted with
protection.outlook.com?

> SMTP error from remote mail server after end of data: host
> eur.olc.protection.outlook.com [104.47.17.97]: 550 5.7.509 Access
> denied, sending domain [NYMPH.PARANOICI.ORG] does not pass DMARC
> verification and has a DMARC policy of reject.

This seems like a quintessential problem with -- what I'll call -- old
school mail forwarding. Something that's becoming more and more fragile
every week.

> There is a way to avoid this?

Presuming that you're using your NYM to send to an address that's
forwarding to another address hosted by protection.outlook.com, then no,
not really as this is almost certainly a problem with how the forwarding
is configured.

Read: This is likely not a problem with mymph.paranoici.org.

--
Grant. . . .

Re: NYM ACCOUNT AND MAIL SERVER

<84f65965edaf21c31401b64f96397482@dizum.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=17982&group=alt.privacy.anon-server#17982

  copy link   Newsgroups: alt.privacy.anon-server
From: nobody@dizum.com (Nomen Nescio)
References: <3eefa36bac194cfdc279ec566f4a2f95@dizum.com>
Subject: Re: NYM ACCOUNT AND MAIL SERVER
Message-ID: <84f65965edaf21c31401b64f96397482@dizum.com>
Date: Mon, 29 Apr 2024 11:32:48 +0200 (CEST)
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!feeder.erje.net!news2.arglkargh.de!alphared!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Nomen Nescio - Mon, 29 Apr 2024 09:32 UTC

On 28 Apr 2024, Nomen Nescio <nobody@dizum.com> posted some
news:3eefa36bac194cfdc279ec566f4a2f95@dizum.com:

> Usually my nyms works well.
> When sending mail, there are few recipients that I can not to reach.
> I receive an error message "Mail delivery failed"
>
> SMTP error from remote mail server after end of data:
> host eur.olc.protection.outlook.com [104.47.17.97]:
> 550 5.7.509 Access denied, sending domain [NYMPH.PARANOICI.ORG] does
> not pass DMARC verification and has a DMARC policy of reject.
>
> There is a way to avoid this?

Possibly not given the nature of anonymous remailers. There are some
challenges because of inbound requirements.

This might be helpful for terminology and an overview how
MS/Azure/Outlook/365 (Whoever they are this year) filter.

https://learn.microsoft.com/en-us/defender-office-365/email-
authentication-spf-configure

Per the error, the addressee you're sending to is in a domain hosted by
MS/Azure/Outlook/365 most likely. This is a picky bitchy bunch and they
will stupidly mimecast flag intra-domain email on occasion requiring a
user to permit one time or all future receipt from the sender in their own
domain. Stupid but it happens.

The email admin responsible for the domain might be able to whitelist
paranoici.org, but that doesn't always work either because of the
additional filtering.

This is an example DMARC DNS record.

"v=DMARC1;p=reject;pct=100;rua=mailto:postmaster@dmarcdomain.com"

paranoici.org SPF and InARP records.

paranoici.org IN TXT v=spf1 redirect=_spf.investici.org

108.222.167.198.in-addr.arpa IN PTR devianza.investici.org

You'll notice paranoici.org does have an spf record. For many that's
sufficient, but not the Outlook bunch, they want both and they better be
syntactically correct. paranoici.org does not have a DMARC record and
therein is one of the problems. Overall the paranoici/investici.org admin
gets + marks for DNS implementation.

What is DMARC?
DMARC uses Sender Policy Framework (SPF) and DomainKeys Identified Mail
(DKIM) to evaluate the authenticity of email messages. Together, these
tools prevent practices like phishing and domain spoofing.

To resolve this issue, the remailer admin would need to make sure that the
NYMPH.PARANOICI.ORG domain is properly configured for DMARC verification.

They can do this by adding a DMARC record to their DNS zone file. The
DMARC record will specify how Outlook should handle emails that fail DMARC
authentication.

"To solve these problems, senders and receivers must share information
with one another. Ideally, receivers supply senders with reporting
information, while senders tell receivers what to do when they receive
unauthenticated messages."

A personal experience, MS/Azure/Outlook/365 ain't for everybody.

My company runs a monitoring system for many different kinds of compute,
storage, network and SAN switches, old and new. We get a lot of email
every day and some systems tend to blab more than others. Reliable
receipt is important for logging to open calls in a timely manner. A
higher level decision was made to move the inbound email from two internal
servers to Outlook hosting, where it promptly failed for 50% of the
inbound because of filtering (And data mangling) we could do nothing to
influence. After a week of wrestling and failing to resolve the issues,
the mail MX records were pointed back to the original servers where they
will remain.

Re: NYM ACCOUNT AND MAIL SERVER

<f2393155592d00948997205351813026@dizum.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=17984&group=alt.privacy.anon-server#17984

  copy link   Newsgroups: alt.privacy.anon-server
From: nobody@dizum.com (Nomen Nescio)
References: <3eefa36bac194cfdc279ec566f4a2f95@dizum.com>
<v0mtjq$t7l$1@tncsrv09.home.tnetconsulting.net>
Subject: Re: NYM ACCOUNT AND MAIL SERVER
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-15"; format=flowed
Content-Transfer-Encoding: 8bit
Message-ID: <f2393155592d00948997205351813026@dizum.com>
Date: Tue, 30 Apr 2024 10:43:02 +0200 (CEST)
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!news2.arglkargh.de!alphared!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Nomen Nescio - Tue, 30 Apr 2024 08:43 UTC

>
> Are those recipients hosted with protection.outlook.com? Or are those
> recipients hosted elsewhere and forwarding to something else hosted with
> protection.outlook.com?

It is possible that someone of my recipients is forwarding to
something.
I wrote to several people all with the same institutional mail
Example: I wrote to
john@somewhere.net
fred@somewhere.net
lynn@somewhere.net
susan@somewhere.net
bob@somewhere.net

and I obtain the DMARC advice only when I send a mail to Lynn.

Re: NYM ACCOUNT AND MAIL SERVER

<20240430.143630.3da5e3d0@mixmin.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=17986&group=alt.privacy.anon-server#17986

  copy link   Newsgroups: alt.privacy.anon-server
Content-Transfer-Encoding: 8bit
X-No-Archive: Yes
Date: Tue, 30 Apr 2024 14:36:30 +0100
Message-Id: <20240430.143630.3da5e3d0@mixmin.net>
References: <3eefa36bac194cfdc279ec566f4a2f95@dizum.com>
<v0mtjq$t7l$1@tncsrv09.home.tnetconsulting.net>
<f2393155592d00948997205351813026@dizum.com>
Subject: Re: NYM ACCOUNT AND MAIL SERVER
Mime-Version: 1.0
From: noreply@mixmin.net (Yamn Remailer)
Content-Type: text/plain; charset=UTF-8; format=flowed
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!nntp.comgw.net!weretis.net!feeder8.news.weretis.net!news.mixmin.net!news2.arglkargh.de!alphared!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Yamn Remailer - Tue, 30 Apr 2024 13:36 UTC

On Tue 30 Apr 2024 11:43 am, Nomen Nescio wrote:
>>
>> Are those recipients hosted with protection.outlook.com?  Or are those
>> recipients hosted elsewhere and forwarding to something else hosted
>> with protection.outlook.com?
>
> It is possible that someone of my recipients is forwarding to something.
> I wrote to several people all with the same institutional mail
> Example: I wrote to
> john@somewhere.net
> fred@somewhere.net
> lynn@somewhere.net
> susan@somewhere.net
> bob@somewhere.net
>
> and I obtain the DMARC advice only when I send a mail to Lynn.
>
How much for an ounce?

Re: NYM ACCOUNT AND MAIL SERVER

<v0s05j$tdi$1@tncsrv09.home.tnetconsulting.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=17990&group=alt.privacy.anon-server#17990

  copy link   Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!tncsrv09.home.tnetconsulting.net!.POSTED.omega.home.tnetconsulting.net!not-for-mail
From: gtaylor@tnetconsulting.net (Grant Taylor)
Newsgroups: alt.privacy.anon-server
Subject: Re: NYM ACCOUNT AND MAIL SERVER
Date: Tue, 30 Apr 2024 18:51:15 -0500
Organization: TNet Consulting
Message-ID: <v0s05j$tdi$1@tncsrv09.home.tnetconsulting.net>
References: <3eefa36bac194cfdc279ec566f4a2f95@dizum.com>
<v0mtjq$t7l$1@tncsrv09.home.tnetconsulting.net>
<f2393155592d00948997205351813026@dizum.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 30 Apr 2024 23:51:15 -0000 (UTC)
Injection-Info: tncsrv09.home.tnetconsulting.net; posting-host="omega.home.tnetconsulting.net:198.18.1.140";
logging-data="30130"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla Thunderbird
Content-Language: en-US
In-Reply-To: <f2393155592d00948997205351813026@dizum.com>
 by: Grant Taylor - Tue, 30 Apr 2024 23:51 UTC

On 4/30/24 03:43, Nomen Nescio wrote:
> I obtain the DMARC advice only when I send a mail to Lynn

Sounds to me like Lynn is forwarding.

If you do an MX lookup for somewhere.net (`dig mx somewhere.net`) do you
see protection.outlook.com servers listed? Or something else?

I speculate that you'll see something else and that Lynn is forwarding
to something that's hosted with protection.outlook.com.

--
Grant. . . .

Re: NYM ACCOUNT AND MAIL SERVER

<ee2601a0b918b0a814b94bdab2cd10fa@dizum.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=18006&group=alt.privacy.anon-server#18006

  copy link   Newsgroups: alt.privacy.anon-server
From: nobody@dizum.com (Nomen Nescio)
References: <3eefa36bac194cfdc279ec566f4a2f95@dizum.com>
<v0mtjq$t7l$1@tncsrv09.home.tnetconsulting.net>
<f2393155592d00948997205351813026@dizum.com>
<v0s05j$tdi$1@tncsrv09.home.tnetconsulting.net>
Subject: Re: NYM ACCOUNT AND MAIL SERVER
Message-ID: <ee2601a0b918b0a814b94bdab2cd10fa@dizum.com>
Date: Sat, 4 May 2024 03:49:46 +0200 (CEST)
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!2.eu.feeder.erje.net!feeder.erje.net!news2.arglkargh.de!alphared!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Nomen Nescio - Sat, 4 May 2024 01:49 UTC

On 30 Apr 2024, Grant Taylor <gtaylor@tnetconsulting.net> posted some
news:v0s05j$tdi$1@tncsrv09.home.tnetconsulting.net:

> On 4/30/24 03:43, Nomen Nescio wrote:
>> I obtain the DMARC advice only when I send a mail to Lynn
>
> Sounds to me like Lynn is forwarding.
>
> If you do an MX lookup for somewhere.net (`dig mx somewhere.net`) do you
> see protection.outlook.com servers listed? Or something else?
>
> I speculate that you'll see something else and that Lynn is forwarding
> to something that's hosted with protection.outlook.com.

I don't get that response when I forward to addresses known to be hosted
on domains filtered by protection.outlook.com. But this is Friday and
tomorrow could be different with the policies and practicies of any
organization run by "Indian Technology Professionals".

My sending domain does have DMARC and SPF records.


computers / alt.privacy.anon-server / Re: NYM ACCOUNT AND MAIL SERVER

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor