Deliverability check: each node asks what the internet sees of it
Deliverability spec (inbuxa-drafts specs/deliverability.md), the server side. Every node that sends mail checks itself once a day, at its own minute in the first hour (UTC), and when an administrator asks: - its outgoing addresses (the connection strategy's, or what its EHLO name resolves to), their reverse DNS and whether it resolves back, and nine blocklists, read by each list's own codes so a refused query is never taken for a listing (DL-1 to DL-6); - for every domain: SPF for each address, each DKIM key (by signing a message that's never sent and verifying it as a receiver would), DMARC, the MTA-STS policy against the MX, TLS reporting, and the domain blocklists (DL-7 to DL-12); - whether it holds a certificate for its EHLO and MX names (DL-13). It keeps one report per node, facts only; the console grades them. - inbuxa:DeliverabilityReport: /get, and a create that asks every node to check now, broadcast as DeliverabilityCheck (DL-15). A tenant administrator gets their own domains only (DL-20). - inbuxa:DeliverabilitySettings: which built-in lists are left out, and the lists themselves (DL-6). - sysDeliverabilityGet, sysDeliverabilityUpdate, sysDeliverabilityCheck; a tenant ceiling always turns the last two off.
This commit is contained in:
1 parent
f791c78d17
commit
a24ed3b60a
34 files changed
+2576
-5
No files matched your search
@@ -123,6 +123,10 @@ impl JmapAuthorization for AccessToken {
|
||||
// inbuxa: accepted security items are read by whoever may
|
||||
// see the server's security settings
|
||||
GetRequestMethod::SecurityAcceptance(_) => Permission::SysSecurityGet,
|
||||
// inbuxa: deliverability spec; the lists are named on the
|
||||
// page that shows the findings, so they read the same way
|
||||
GetRequestMethod::DeliverabilityReport(_)
|
||||
| GetRequestMethod::DeliverabilitySettings(_) => Permission::SysDeliverabilityGet,
|
||||
// inbuxa: legacy protocols off. It takes listeners away and
|
||||
// puts them back, so it takes the listener's permissions
|
||||
GetRequestMethod::ProtocolPolicy(_) => Permission::SysNetworkListenerGet,
|
||||
@@ -335,6 +339,23 @@ impl JmapAuthorization for AccessToken {
|
||||
.details("You are not authorized to accept security items"))
|
||||
}
|
||||
}
|
||||
// inbuxa: DL-15: a create runs the check; the handler
|
||||
// refuses the rest
|
||||
SetRequestMethod::DeliverabilityReport(s) => validate_set(
|
||||
s,
|
||||
self,
|
||||
Permission::SysDeliverabilityCheck,
|
||||
Permission::SysDeliverabilityCheck,
|
||||
Permission::SysDeliverabilityCheck,
|
||||
),
|
||||
// inbuxa: DL-6, which lists are asked
|
||||
SetRequestMethod::DeliverabilitySettings(s) => validate_set(
|
||||
s,
|
||||
self,
|
||||
Permission::SysDeliverabilityUpdate,
|
||||
Permission::SysDeliverabilityUpdate,
|
||||
Permission::SysDeliverabilityUpdate,
|
||||
),
|
||||
// inbuxa: LH-12, exporting held data
|
||||
SetRequestMethod::HoldExport(s) => validate_set(
|
||||
s,
|
||||
@@ -506,6 +527,8 @@ impl JmapAuthorization for AccessToken {
|
||||
| MethodObject::HoldExport
|
||||
| MethodObject::MailRule
|
||||
| MethodObject::SecurityAcceptance
|
||||
| MethodObject::DeliverabilityReport
|
||||
| MethodObject::DeliverabilitySettings
|
||||
| MethodObject::HeldMessage
|
||||
| MethodObject::Journal
|
||||
| MethodObject::JournalEntry
|
||||
|
||||
Reference in new issue
Block a user