Boosted by @welcome@friends.deko.cloud
#introduction
Hi, I'm Merten. I've been a software engineer for 24+ years, and earlier this year I very nearly got taken by a phishing scam. I caught it late enough that it genuinely rattled me, and the fact that I came that close at all got me wondering why this is still a problem after all this time. If all that experience isn't enough to save you, it probably isn't a user-education problem.
What I found was that SMTP has never had a way to prove who actually sent a message. SPF, DKIM and DMARC all check the domain and the server, but never the person, so a lookalike domain can pass all three and still land in your inbox looking perfectly fine. Everything built since has been trying to guess at the answer from the outside, which is a good part of why we are all still guessing.
I couldn't find anyone working on that particular part, so I thought I'd have a go at it myself. I've always found that turning something intricate into something simple is where the real value is, and the simple version here is that the address is a keypair, verifiable all the way up to its domain and the servers hosting it, so a message either checks out against the sender's key or it doesn't. There's a spec and a reference server, both Apache-2.0, and it'll run in a single container if you'd like to poke at it.
I moonlight on it, so it moves at evenings-and-weekends pace. I'll mostly be posting about mail infrastructure and protocol design, and occasionally about being wrong on both.
If you spot something I've got wrong, I'd genuinely like to hear it.
Spec, code and docs are all at https://dmcn.dev
#infosec #email #identity #dmcn