head	1.34;
access;
symbols
	pkgsrc-2026Q3:1.34.0.2
	pkgsrc-2026Q3-base:1.34
	pkgsrc-2026Q2:1.30.0.2
	pkgsrc-2026Q2-base:1.30
	pkgsrc-2026Q1:1.27.0.2
	pkgsrc-2026Q1-base:1.27
	pkgsrc-2025Q4:1.22.0.2
	pkgsrc-2025Q4-base:1.22
	pkgsrc-2025Q3:1.17.0.2
	pkgsrc-2025Q3-base:1.17
	pkgsrc-2025Q2:1.14.0.2
	pkgsrc-2025Q2-base:1.14
	pkgsrc-2025Q1:1.12.0.2
	pkgsrc-2025Q1-base:1.12
	pkgsrc-2024Q4:1.9.0.2
	pkgsrc-2024Q4-base:1.9
	pkgsrc-2024Q3:1.5.0.2
	pkgsrc-2024Q3-base:1.5
	pkgsrc-2024Q2:1.3.0.4
	pkgsrc-2024Q2-base:1.3
	pkgsrc-2024Q1:1.3.0.2
	pkgsrc-2024Q1-base:1.3
	pkgsrc-2023Q4:1.2.0.10
	pkgsrc-2023Q4-base:1.2
	pkgsrc-2023Q3:1.2.0.8
	pkgsrc-2023Q3-base:1.2
	pkgsrc-2023Q2:1.2.0.6
	pkgsrc-2023Q2-base:1.2
	pkgsrc-2023Q1:1.2.0.4
	pkgsrc-2023Q1-base:1.2
	pkgsrc-2022Q4:1.2.0.2
	pkgsrc-2022Q4-base:1.2
	pkgsrc-2022Q3:1.1.0.2
	pkgsrc-2022Q3-base:1.1;
locks; strict;
comment	@# @;


1.34
date	2026.09.10.07.27.43;	author adam;	state Exp;
branches;
next	1.33;
commitid	cpc41A7JUD5mU2VG;

1.33
date	2026.08.11.15.47.05;	author adam;	state Exp;
branches;
next	1.32;
commitid	8UglWjzcChtCDeRG;

1.32
date	2026.06.29.10.08.58;	author adam;	state Exp;
branches;
next	1.31;
commitid	DsGHgFAngAZe9GLG;

1.31
date	2026.06.22.12.17.03;	author adam;	state Exp;
branches;
next	1.30;
commitid	uDW2BfAP5mMb5NKG;

1.30
date	2026.05.25.07.46.27;	author adam;	state Exp;
branches;
next	1.29;
commitid	0U8RZakp8of8uaHG;

1.29
date	2026.05.05.18.06.43;	author adam;	state Exp;
branches;
next	1.28;
commitid	LuhJHLTZIRKQyEEG;

1.28
date	2026.04.28.10.08.26;	author adam;	state Exp;
branches;
next	1.27;
commitid	XYshzGe8LfFI8IDG;

1.27
date	2026.02.25.13.41.49;	author adam;	state Exp;
branches;
next	1.26;
commitid	oWyu6q3ZAxhrjLvG;

1.26
date	2026.01.26.20.17.25;	author adam;	state Exp;
branches;
next	1.25;
commitid	3vaTCvJwfKXXsWrG;

1.25
date	2026.01.11.10.07.06;	author adam;	state Exp;
branches;
next	1.24;
commitid	Cp9B21BdGcjvzXpG;

1.24
date	2025.12.30.12.55.13;	author adam;	state Exp;
branches;
next	1.23;
commitid	chp991riAxz5TqoG;

1.23
date	2025.12.22.06.00.56;	author adam;	state Exp;
branches;
next	1.22;
commitid	29MM1sS1RFGIQmnG;

1.22
date	2025.12.05.11.28.40;	author adam;	state Exp;
branches;
next	1.21;
commitid	jqBFUkDclYc5ddlG;

1.21
date	2025.11.12.17.30.26;	author adam;	state Exp;
branches;
next	1.20;
commitid	5bsmneK24fm9XhiG;

1.20
date	2025.10.30.11.40.52;	author adam;	state Exp;
branches;
next	1.19;
commitid	MLwFbW3Ft4q4rAgG;

1.19
date	2025.10.03.05.44.49;	author adam;	state Exp;
branches;
next	1.18;
commitid	3G2OXoZrhSOMk5dG;

1.18
date	2025.09.22.14.40.31;	author adam;	state Exp;
branches;
next	1.17;
commitid	hQlvg9pXoIJsEIbG;

1.17
date	2025.09.14.06.52.24;	author adam;	state Exp;
branches;
next	1.16;
commitid	13bcVnOsxTUKjEaG;

1.16
date	2025.08.28.10.23.03;	author adam;	state Exp;
branches;
next	1.15;
commitid	fyMuKMNORyfT1u8G;

1.15
date	2025.08.25.17.05.54;	author adam;	state Exp;
branches;
next	1.14;
commitid	m7yuDY7DyC19m88G;

1.14
date	2025.06.05.18.10.29;	author adam;	state Exp;
branches;
next	1.13;
commitid	TIDdhcMELcXJjJXF;

1.13
date	2025.05.21.07.01.20;	author adam;	state Exp;
branches;
next	1.12;
commitid	ceQ3U2lexOf66KVF;

1.12
date	2025.03.03.13.04.15;	author adam;	state Exp;
branches;
next	1.11;
commitid	DSbcQ9O9Iq02ECLF;

1.11
date	2025.02.26.10.11.23;	author adam;	state Exp;
branches;
next	1.10;
commitid	7We7KAHmmtZHQXKF;

1.10
date	2024.12.30.14.33.41;	author adam;	state Exp;
branches;
next	1.9;
commitid	bLsGob7UtheaaxDF;

1.9
date	2024.11.08.14.17.29;	author adam;	state Exp;
branches;
next	1.8;
commitid	h3QIVXKiaA4gKQwF;

1.8
date	2024.10.31.10.42.40;	author adam;	state Exp;
branches;
next	1.7;
commitid	tfgtT6fGDiGoONvF;

1.7
date	2024.10.29.09.50.05;	author adam;	state Exp;
branches;
next	1.6;
commitid	swKcAUEiDQcwAxvF;

1.6
date	2024.10.28.20.47.31;	author adam;	state Exp;
branches;
next	1.5;
commitid	98Gr0F00oOpUftvF;

1.5
date	2024.08.20.07.14.11;	author adam;	state Exp;
branches;
next	1.4;
commitid	ULw2gc3UoNdAYwmF;

1.4
date	2024.07.20.06.20.22;	author adam;	state Exp;
branches;
next	1.3;
commitid	sOtcJVpzKy2OFxiF;

1.3
date	2024.02.22.13.12.25;	author adam;	state Exp;
branches;
next	1.2;
commitid	9EqM7OJNPeW6KqZE;

1.2
date	2022.11.30.10.38.49;	author adam;	state Exp;
branches;
next	1.1;
commitid	B96nyisqfRLdkI3E;

1.1
date	2022.08.24.10.18.34;	author wiz;	state Exp;
branches;
next	;
commitid	aH5SpU1od1ZIm7RD;


desc
@@


1.34
log
@py-checkdmarc: updated to 6.0.1

6.0.1

Fixed

SPF: the RFC 6652 reporting modifiers ra=, rp=, and rr=, added in 5.8.0 and removed later, are recognized again; their values are validated against RFC 6652 §3 (rp= per erratum 6579) and surfaced in the parsed result as ra, rp, and rr next to exp, and a malformed value is warned about and ignored instead of failing the record. Warnings also cover the two RFC 6652 §3 semantic rules — rp= and rr= do nothing without ra=, and ra= is ignored in a record reached through an include — and exp= and these modifiers are now honored after all in any order

6.0.0

An RFC conformance audit compared every module line-by-line against its governing specification (SPF: RFC 7208; DMARC: RFC 9989/9990; TLSRPT: RFC 8460; MTA-STS: RFC 8461; SMTP/MX: RFC 5321/7505/2181; DNSSEC: RFC 4033-4035; SOA: RFC 1035/2181; BIMI: draft-brand-indicators-14) and found 81 discrepancies, most confirmed by executing the old code. This release fixes all of them. Many fixes change validation verdicts — records the specs call valid are no longer rejected, and records they call invalid are no longer accepted — hence the major version. This release also contains everything staged for 5.18.0, which was never released.

Breaking changes

MX STARTTLS/TLS testing is now opt-in: pass --check-mx-tls on the CLI or check_mx_tls=True to check_domains(), check_mx(), or get_mx_hosts(). The --skip-tls flag and skip_tls parameter are still accepted but do nothing, and passing skip_tls emits a DeprecationWarning. As a result, MX host results no longer carry the tls and starttls keys, and the CSV tls/starttls columns are empty, unless TLS testing is turned on
check_dnssec() performs a real chain-of-trust check anchored at the parent zone's DS record instead of verifying a zone's DNSKEY against itself. A zone with no DS at its parent (including "island of security" zones) is insecure per RFC 4033 §4.3 and returns False; a broken zone such as dnssec-failed.org returns False through any resolver, where it previously returned True through non-validating resolvers. Bogus (SERVFAIL with DS present) is now warned about distinctly from unsigned
Unknown and extension tags/fields now parse with a warning instead of failing validation, as each spec requires: SPF unknown modifiers (RFC 7208 §6), DMARC unknown tags (RFC 9989 §4.7), TLSRPT extension fields (RFC 8460 §3), MTA-STS extension fields and policy keys (RFC 8461 §3.2), and BIMI unknown tags (draft §4.3). An unknown field is ignored only when it fits the spec's own extension grammar; a malformed extension name or value still fails the record or policy
A TXT record unrelated to the record type being queried is now discarded instead of failing validation, per each spec's discard rule: TLSRPT (RFC 8460 §3.1), MTA-STS (RFC 8461 §3.1), BIMI (draft §7.2), and DMARC report authorization records (RFC 9990 §4). Each query also now returns the record carrying the version tag rather than whichever TXT record the resolver listed first. When a real record sits beside the unrelated one, the unrelated record is reported as a warning; when it is the only record present, the check reports that no record exists. DMARC authorization records are discarded silently, and a wildcard authorization record that is unrelated is still an error. Callers catching UnrelatedTXTRecordFoundAtTLSRPT or UnrelatedTXTRecordFoundAtBIMI should note that those queries now raise SMTPTLSReportingRecordNotFound and BIMIRecordNotFound instead
Records the old code wrongly accepted are now invalid: SPF records exceeding the 10-DNS-lookup limit through a, ptr, or macro-valued terms (RFC 7208 §4.6.4 — the limit was previously only enforced for some mechanism types), SPF include of a domain with no SPF record (permerror per RFC 7208 §5.2), MTA-STS policies missing a required key (RFC 8461 §3.2 — the check was dead code), BIMI records missing the required l= tag (draft §4.3), lowercase v=dmarc1 (RFC 9989 §4.8), and an SPF qualifier on a modifier or a value on the all mechanism (RFC 7208 §12)
MTA-STS and TLSRPT records are now matched case-sensitively, with no whitespace allowed around the version tag's =, because RFC 8461 §3.1 and RFC 8460 §3 spell those literals with the case-sensitive %s notation of RFC 7405. Records such as V=STSv1; id=…, v = STSv1; id=…, v=STSv1; ID=…, and v=TLSRPTv1; RUA=… parsed before and are now syntax errors. DMARC is unaffected: RFC 9989 §4.8 makes its tag names case-insensitive and allows whitespace around =, which this release starts honoring
The DMARC tree walk now applies RFC 9989 §4.10.2 Organizational Domain selection (psd=n wins; a psd=y record hands off to the record one label below it, warning when none is published there; otherwise the record with the fewest labels applies) instead of stopping at the closest parent record, which selected the opposite policy in the RFC's own worked example
Added

--check-mx-tls CLI flag and check_mx_tls API parameter (see breaking changes)
get_mx_record_set() in checkdmarc.utils, returning MX hosts, warnings, null MX status, and the number of MX records in the answer (the new MXRecordSet type), parsed from dnspython rdata instead of text splitting. The record count is what separates "no MX records at all" from "MX records that produced no usable host"
Null MX (RFC 7505) handling: a lone 0 . record yields an explicit "does not accept mail" warning distinct from having no MX records (which now notes the RFC 5321 §5.1 implicit MX rule); a null MX coexisting with other MX records is flagged as an RFC 7505 §3 violation instead of producing an empty-hostname host entry; a root (.) target with a non-zero preference, such as 10 ., is warned about as malformed instead of becoming an empty-hostname host entry
MX target sanity warnings: IP-address literals (RFC 5321 §5.1), hostnames failing RFC 5321 §2.3.5 label syntax, and targets that are CNAME aliases (RFC 2181 §10.3)
DNS over HTTPS (DoH) and DNS over TLS (DoT) support through the existing nameservers option, matching parsedmarc. Each entry picks its own transport: an IP address means plain DNS on port 53 exactly as before, an https:// URL means DoH, and tls://ip[:port][#hostname] means DoT, where the port defaults to 853 and the optional #hostname names the server's TLS certificate identity, matching systemd-resolved's syntax. DoH queries go through a shared httpx client that honors the HTTP_PROXY/HTTPS_PROXY/NO_PROXY and SSL_CERT_FILE/SSL_CERT_DIR environment variables, so checks can run on networks that block outbound DNS but provide an HTTP proxy. The DNSSEC, DNSKEY, and TLSA checks use the configured transports too. The dnspython requirement is now dnspython[doh]>=2.7.0, and httpx>=0.26.0 is a new direct dependency for the shared DoH client
Changed

Update the GitHub Actions used by the workflows to their latest major versions: checkout v7, setup-python v7, codecov-action v7, upload-artifact v7, download-artifact v8, configure-pages v6, upload-pages-artifact v5, and deploy-pages v5. Most now run on Node.js 24 (upload-pages-artifact and codecov-action are composite actions). The deprecated codecov/test-results-action is replaced by codecov/codecov-action@@v7 with report_type: test_results, which is the same upload it performed before; no other workflow behavior changes
Renamed identifiers whose names misdescribed what they hold, keeping the old names as deprecated aliases where they were public API:
checkdmarc.dnssec.check_dnssec() replaces test_dnssec(), matching every other module's check_*() entry point; test_dnssec() remains as a deprecated alias that warns
get_mx_hosts() takes approved_mx_hostnames, matching check_mx() and check_domains(); the old approved_hostnames keyword remains as a deprecated alias that warns
The CLI accepts --nameservers as an alias for -n/--nameserver, and --approved-ns/--approved-mx as clearer aliases for --ns/--mx
MTASTSQueryResult, MTASTSCheckResult, SMTPTLSReportingQueryResult, and SMTPTLSReportingResult replace their plural forms, matching the singular BIMI result types; the plural names remain as aliases
MTA_STS_TAGS and SMTP_TLS_REPORTING_TAGS replace the lowercase mta_sts_tags and smtp_rpt_tags constants, matching BIMI_TAGS; the lowercase names remain as aliases
The MXHost type now declares the fields MX host dicts actually carry (addresses, dnssec, tlsa, tls, starttls as optional keys, with hostname and preference required in a new MXRecord base); the declared ip_addresses field never existed in any produced data
Removed unused module-level copies of the DMARC grammar internals (checkdmarc.dmarc.version_tag, tag_value, and START), which duplicated the private grammar class and shadow-collided with unrelated locals
Many internal variables renamed so a name no longer changes type or meaning mid-function (split results, parse results, pyleri grammar results, joined display strings); no behavior changes
Removed

The pyopenssl dependency, as planned in 5.17.5. checkdmarc stopped importing pyOpenSSL in that release; the floor was kept for one release only so upgrades would also move any leftover pyOpenSSL to a version compatible with cryptography 50
Fixed

SPF: the 10-lookup and 2-void-lookup limits are enforced after every counted term rather than in some branches only; redirect is ignored when an all mechanism is present (RFC 7208 §6.1); a v=spf10-style sibling TXT record is discarded instead of hiding a valid record (§4.5); multiple all mechanisms are valid with first-match semantics (§4.6.2); terms after all are no longer processed or counted; duplicate includes count their lookups like real evaluation; the term-value charset matches the §12 ABNF (so %{ir=} and ! parse); exp-only macro letters c/r/t are rejected outside exp text (§7.2); the uppercase R transformer is accepted; exp is honored anywhere in the record and its name is matched case-insensitively after all (§4.6.1); mx CIDR suffixes are stripped before the DNS query instead of being sent as part of the name; dual-CIDR lengths and leading-zero CIDRs are validated; empty a:/mx:/ptr: domain-specs are rejected; an MX host with no A/AAAA records is a warning rather than a void DNS lookup, because §4.6.4 counts void lookups per term query, so records that used to fail the 2-void limit for that reason now pass; and a domain-spec that is not a fully qualified domain name (such as exists:localhost) is warned about, since receivers may treat it as a no-match (§4.8)
DMARC: the grammar matches the §4.8 ABNF (any-length tag names, full value charset — mandatory percent-encoding like %2C in report URIs now parses, and bare v=DMARC1 is valid); non-mailto report URIs are kept with a warning instead of invalidating the record (§4.7) and are validated against the RFC 3986 URI structure (scheme, authority with a real IP-literal when bracketed, path, query, and at most one fragment); rua/ruf values keep the case they were published with instead of being lowercased along with other tag values, since RFC 3986 makes only the scheme and host case-insensitive; invalid adkim/aspf values fall back to r with a warning; fo=0:1 is reported as invalid (mutually exclusive), not "redundant", and a repeated value such as fo=1:1 is invalid too; both fall back to fo=0 with a warning; the record-detection filter tolerates ABNF-legal whitespace and case around v=; an unrelated TXT record no longer causes a false "authorization record not found"; an NXDOMAIN on the courtesy apex query no longer discards an already-found record; two citations to nonexistent RFC sections corrected
BIMI: the organizational-domain fallback keeps the caller's selector instead of reverting to default (draft §7.2 step 6); the SVG-vs-certificate logotype hash check is tag-order-independent and hashes the raw bytes; SVG file size is measured in actual bytes instead of sys.getsizeof of a decoded string; the raw SVG bytes are handed to the XML parser instead of a lossy errors="ignore" decode, so malformed bytes fail validation rather than being silently dropped, and non-UTF-8 encodings declared in the XML declaration parse correctly; the pct warning fires only for p=quarantine per §7.1 step 9; empty lps= parses to an empty list; l=/a= URIs are validated against the bimi-uri ABNF (no raw spaces or unencoded commas, at most one # per RFC 3986); an IP-literal host is rejected in a=, whose prose requires an FQDN, but allowed in l=, which imports the URI grammar with no FQDN rule; unknown tags are ignored only when they fit the DKIM tag-value grammar the draft imports (RFC 6376 §3.2: no . or - in tag names, no control characters in values); the PEM-bytes certificate path reads the leaf certificate
MTA-STS: the policy fetch no longer follows redirects and requires HTTP 200 exactly (RFC 8461 §3.3); MX pattern matching is anchored with * matching a single label, so *.example.com no longer matches mail.example.com.evil.com (§4.1); a TXT record without id returns valid: False instead of crashing; duplicate fields are first-wins with a warning (§3.2); mixed LF/CRLF policies parse; mx values are validated against the ["*."] Domain ABNF with each label capped at 63 octets (RFC 1035 §2.3.4); record detection keys on v=STSv1; including the semicolon, while the grammar-legal v=STSv1 ; form is accepted with a warning that senders applying the §3.1 discard rule literally will ignore the record; a policy field value may contain colons, since §3.2 separates the name from the value at the first colon; the query raises SPFRecordFoundWhereMTASTSRecordShouldBe when an SPF record sits at the MTA-STS name; id is capped at 32 alphanumerics; max_age accepts only plain digits; a CR that is not part of a CRLF line ending (such as \r\r\n) is a policy syntax error instead of being silently stripped (§3.2); whitespace before a policy field name or between the name and the colon is a syntax error, since the §3.2 delimiter is ":" *WSP
TLSRPT: whitespace around commas between rua URIs is accepted per the §3 ABNF; repeated rua fields merge their destinations, since §3 supports declaring more than one rua (other repeated tags still warn with first-wins); record detection keys on v=TLSRPTv1; per §3.1, while the grammar-legal v=TLSRPTv1 ; form is accepted with a warning that senders applying the discard rule literally will ignore the record; URI validation is anchored so garbage-prefixed schemes are rejected; a bracketed https authority must be a real IPv6 address (RFC 4291) and # may appear only once, as the RFC 3986 fragment delimiter; a mailto local part follows the RFC 5322 dot-atom rules (no leading, trailing, or doubled dots); the parser returns the matching TLSRPT record instead of whichever TXT record sorted first
SMTP: negative STARTTLS results are cached like positive ones; the port-465 fallback failure warning names the implicit-TLS probe instead of reading as a port 25 failure
SOA: check_soa() walks from the domain up through each ancestor to the base domain and reports the first SOA it finds, so a delegated child zone reports its own SOA and contact rather than the base domain's (RFC 2181 §7); soa_rname_to_email() handles RFC 1035 §5.1 escapes, including an escaped backslash before a real label separator, and quotes a decoded local part that is not a plain dot-atom (RFC 5322 §3.2.4) so the returned address is always syntactically valid; escapes in the domain labels are decoded too, with each label validated on its own before joining so an escaped dot (one DNS label holding a literal dot) is an error rather than silently moving the label boundary to a different mailbox domain
DNSSEC: caller-supplied caches are forwarded to get_dnskey(); the dnssec result-key documentation states what the boolean actually means; a nameserver answering REFUSED, FORMERR, or the like is treated as a failed attempt and the next nameserver is tried, instead of the error being mistaken for a clean empty answer that means "no records". This applies to the chain check, get_dnskey(), and get_tlsa_records() alike: previously the first server's error ended the lookup, so a second nameserver holding the answer was never asked, and get_dnskey() cached the failure as though the zone were unsigned. A lookup that could not complete is no longer cached at all. In the chain check a SERVFAIL is still reported as bogus when the parent publishes a DS record, while a SERVFAIL on the DS query itself is reported as a check that could not complete. TLSA records whose signature does not verify are now reported as such rather than being logged as a query error; the record types consulted below a zone apex now include AAAA and TXT, so a name whose only signed record set is one of those is no longer reported as uncovered
An SPF a mechanism's CIDR suffix now applies to the returned addresses. A split result was reassigned over the same variable, so the length check inspected the hostname string: a:example.com/24 silently lost its suffix, a two-character hostname had its second character used as one, and a/24 failed to default to the current domain
The DNS_CACHE_MAX_AGE_SECONDS environment variable now actually configures the DNS cache, which was wired to the DNSSEC constant, so the documented variable had no effect and DNSSEC_CACHE_MAX_AGE_SECONDS silently controlled both caches
The domains field of BIMI certificate metadata now stays a list when the checked domain does not match the certificate; building the error message rebound the list to a joined string. That message now separates the domains with commas rather than periods
MTA-STS policy mx values are now validated against the whole value instead of any substring; an unanchored search accepted any value containing a single legal character, so mx: not a hostname! passed as an MX entry, and the "Invalid mx value" error was nearly unreachable
parse_mta_sts_record()'s docstring no longer claims tag values carry descriptions; MTA-STS tag values are plain strings and include_tag_descriptions currently adds none
An SPF exp modifier with an empty value (exp=) now raises SPFSyntaxError as intended; the check compared the value to the integer 0, which never matches a string, so the empty modifier was silently accepted
A BIMI record with an empty l tag no longer warns about DMARC policy requirements that only apply when a logo is published; the check compared the tag's dict to an empty string, which is always unequal. (A record with no l tag at all is now rejected outright — see the breaking changes above — where it previously crashed with a KeyError on this comparison)
check_bimi() no longer discards the warnings raised while locating the record — an unrelated TXT record beside it, or a record published at the root of the domain — by overwriting them with the parser's warnings. check_mta_sts() already merged both sets
A certificate's wordMark attribute is now labeled wordMark in BIMI certificate metadata instead of its raw dotted OID string; a trailing comma made the label table's key a one-element tuple
check_mta_sts() no longer passes its DNS timeout as the HTTP timeout for the policy download; the download uses DEFAULT_HTTP_TIMEOUT, as the BIMI check already did
DMARCRecordNotFound now calls its parent constructor, so its message is carried explicitly rather than through a CPython quirk and its data attribute exists like other DMARC errors
SOA range and type errors now name the field that failed (retry, expire, or minimum) instead of always naming refresh
The BIMI check's DMARC policy warning stated the opposite of the requirement; it now reads "The DMARC policy (p tag) must be set to quarantine or reject"
The certificate metadata field for the X.509 subjectAlternativeName extension was misspelled serviceAlternativeName; code reading that key from BIMI certificate results should update
The User-Agent header sent on HTTP requests had doubled parentheses around the OS name
The example authorization record in the "does not indicate that it accepts DMARC reports" error contained a stray quote and a run of spaces from a misplaced line continuation
SPF TXT length warnings now report sizes in bytes, matching what is measured and what RFC 7208 § 3.3 limits, instead of calling them characters
Cleaned up user-facing messages across the package: corrected articles ("Found an SPF record…"), IPv4/IPv6 capitalization, double spaces, missing periods, inconsistent RFC citation punctuation, the garbled DMARC fo tag redundancy warning, and the parked-domain MX warning, which now reads "MX records found on a parked domain"
Corrected inaccurate docstrings throughout: copy-paste artifacts ("MTA-HTS", "SIS-MTA", "Tne", the wrong TLSRPT record location), missing parameters and return keys, the stale claim that BIMI file content is not analyzed, and wrong exception cross-references
Fixed documentation drift: the CLI usage block in the docs was missing --retries and is now generated from the real --help output, the docs index pointed at a nonexistent CI workflow badge, and README/docs typos are corrected
@
text
@$NetBSD: distinfo,v 1.33 2026/08/11 15:47:05 adam Exp $

BLAKE2s (checkdmarc-6.0.1.tar.gz) = 98804fb0bd7bf1e20da643af343b8e3705cfaf946436cd2fb51e671b0004e22b
SHA512 (checkdmarc-6.0.1.tar.gz) = 14f7574fa12b166b8b5b73d75c83b0a9016ed991d80155a08447e7375357c2baf3f41da23c6cc38c82aa3f02eafcb2fa64380aa07fc7aa9d025f0396c21626f3
Size (checkdmarc-6.0.1.tar.gz) = 96769 bytes
@


1.33
log
@py-checkdmarc: updated to 5.17.4

5.17.4

Highlights

Checking a domain whose DNS answer holds a chain of names — aws.amazon.com and bka.de were the reported cases — raised AttributeError: 'NoneType' object has no attribute 'name' and aborted the whole run. The DNSSEC code inferred what an answer contained by counting record sets, so a two-record answer with no signature in it was handed to the validator. Records are now selected by name and type.
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.32 2026/06/29 10:08:58 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.17.4.tar.gz) = 8301613fffc506597cc31d70abd3dee35416553a8eafa2a3b29954ccd5b9467a
SHA512 (checkdmarc-5.17.4.tar.gz) = 4cd6b3fb7029e12e58cc4f3a46ea6011823bb92c76a02bf6b09d6d812ba65e7125643ec1b1bf7402837ff94a31df3b1150fdb4a1b27ee65239d44b080d6029b0
Size (checkdmarc-5.17.4.tar.gz) = 66658 bytes
@


1.32
log
@py-checkdmarc: updated to 5.17.3

5.17.3

Changed

Narrow the advisory SPF record size check to catch only UnicodeError (raised when a record can't be encoded to UTF-8) instead of swallowing every exception, and log the skip at debug level
Replace the remaining broad except Exception handlers across the package with the specific exception types each block can recover from, so unexpected programming errors surface instead of being masked. As a result, intentional record-validation errors (e.g. MultipleSPFRTXTRecords, MTASTSRecordInWrongLocation) now propagate as their own types rather than being converted to a generic "record not found" error
Modernize type annotations to PEP 604 syntax (X | None and X | Y instead of Optional[X] and Union[X, Y]) throughout the package

Fixed

Declare the supported Python floor with the correct requires-python key (the previous python_requires key is not recognized in a PEP 621 [project] table, so the published metadata advertised no minimum and pip would install on end-of-life Python versions where the modern type-alias syntax fails). Also add per-version Python classifiers for 3.10–3.14

5.17.2

Fixed

Discard TXT records with leading whitespace instead of treating them as valid SPF records, since RFC 7208 section 4.5 requires a record to begin with exactly v=spf1

Security

Require cryptography>=48.0.1 to avoid the vulnerable OpenSSL bundled in earlier cryptography wheels
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.31 2026/06/22 12:17:03 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.17.3.tar.gz) = 0d684ae3a41e91fa4e55c53b112efa3ea9adae39de49efb6f1ee082e3f93846e
SHA512 (checkdmarc-5.17.3.tar.gz) = e2c6a06e2c324bda60a5171ed3c635ba885c1d8073431db1791ecea4a4d8bee0620088c273a4474eccb0d2e72792f9e6e164c8eac0d3a4ffca1487eeb7b3f358
Size (checkdmarc-5.17.3.tar.gz) = 66061 bytes
@


1.31
log
@py-checkdmarc: updated to 5.17.1

5.17.1

Fixed

Accept uppercase SPF macro letters (e.g. %{S}), which are valid per RFC 7208 section 7.3

5.17.0

Added

Warnings for deprecated Sender ID TXT records

Changed

NXDOMAIN errors are more detailed
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.30 2026/05/25 07:46:27 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.17.1.tar.gz) = edb0473465428033337a3b268c3a63cbc9902eeec96299ec086152922a12a93e
SHA512 (checkdmarc-5.17.1.tar.gz) = 3e3cee5ae7250d79db9030bf8236c115f416f2eb993b480e802e897b92c69e9f8bda8c3a37143c4b53baa26781cce37460db2e862c1c18c1e1da34d55e76bf0c
Size (checkdmarc-5.17.1.tar.gz) = 65809 bytes
@


1.30
log
@py-checkdmarc: updated to 5.16.2

5.16.2

BIMI: forbidden x/y attributes on the root <svg> element are now actually rejected. get_svg_metadata was reading the wrong xmltodict keys, so the existing rejection in check_svg_requirements never fired on real SVGs. The metadata also lost the y value to a typo that clobbered metadata["x"].
DNSSEC: narrowed three broad except Exception clauses to specific exception types (dns.exception.DNSException, OSError, EOFError) so programming errors propagate instead of being silently swallowed.

5.16.1

Simplify the warning emitted for pct/rf/ri to just "Support for the {tag} tag was removed in RFC 9989".

5.16.0

Rename DMARCbis references to RFC 9989
In compliance with RFC 9989, treat a DMARC p tag as p=none, instead of requiring it
Instead, a warning is raised that older versions of DMARC require it
DMARC: the pct, rf, and ri tags are removed in RFC 9989. They are no longer implicitly added to parsed results, are no longer strictly validated (invalid values that previously raised now just warn), and explicit use emits a "removed in RFC 9989" warning. Pre-9989 readers may still honor them, so the value is left intact for those consumers.
DMARC: unknown tags are now ignored with a warning instead of raising InvalidDMARCTag, per RFC 9989 ("Unknown tags MUST be ignored").
DMARC: the order constraint that p must immediately follow v is now a warning rather than a hard syntax error. RFC 9989 permits any tag ordering after v; older RFC 7489 readers may still expect p second.
DMARC: the !size suffix on rua/ruf URIs is now flagged as obsolete syntax (RFC 9989 says reporters MUST ignore it). The warning still fires because pre-9989 readers may still honor it.
DMARC: the RFC 9989 tree walk now continues all the way to single-label parents (TLDs). PSD operators publish their policy at e.g. _dmarc.gov with psd=y, and the previous "don't query TLDs" short-circuit prevented PSD discovery (the main reason RFC 9989 added the tree walk).
DMARC: during the tree walk, parent queries no longer trigger the apex-fallback "wrong-location" check. A stray v=DMARC1 at a parent domain's apex used to spuriously abort the walk with DMARCRecordInWrongLocation; that check is now only applied to the originally requested name.
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.29 2026/05/05 18:06:43 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.16.2.tar.gz) = 4e52074ecd2baaf62654606de8e790ee3d1c121da31d829307efcc2ce67f8512
SHA512 (checkdmarc-5.16.2.tar.gz) = 290c404ebeb1e598c705653f499c59b6e286e47d60085c04031a59237d0c133982ebf1f22b6f81da23ea343828219e1856eeb6b7ff4ef236297fc5e70d802d54
Size (checkdmarc-5.16.2.tar.gz) = 65456 bytes
@


1.29
log
@py-checkdmarc: updated to 5.15.3

5.15.3
Fixes
Display a warning is a BIMI image is provided without a VMC/CMC
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.28 2026/04/28 10:08:26 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.15.3.tar.gz) = 1b596f7703d1bbcc1bb8ba1a4d671d57b83462babc32686106e448b16ed86aeb
SHA512 (checkdmarc-5.15.3.tar.gz) = 2d4aabcb613d34c26de434f650dc3a5348a358af9f8c1e4a03469fe42799aabf8a978dcbce82cef922cae764a4546f4fb1ce325e6446fc7ac361cedd6496483f
Size (checkdmarc-5.15.3.tar.gz) = 64130 bytes
@


1.28
log
@py-checkdmarc: updated to 5.15.2

5.15.2

Cap the per-query UDP timeout at min(1.0, timeout) for single-nameserver
configurations as well as multi-nameserver ones. Previously, when only one
nameserver was configured (or the system default list had a single entry),
resolver.timeout and resolver.lifetime were both set to the full
timeout budget, which collapses dnspython's UDP retry loop to a single
attempt — a single dropped UDP datagram then consumed the whole lifetime
and raised LifetimeTimeout, while dig (which defaults to +tries=3)
would mask the same blip by retrying. dnspython now retries UDP within
the lifetime window (~2 attempts at the default 2s budget), matching
dig's behavior in spirit and eliminating spurious single-NS timeouts
on paths with occasional packet loss.
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.27 2026/02/25 13:41:49 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.15.2.tar.gz) = 05b3f900826f48f070c914c6864f5af0cbc0b6aca37462bb772673e42a1c6c3c
SHA512 (checkdmarc-5.15.2.tar.gz) = 830dfaee63bcae88251af10a817b93c27bd13c3faf0098f5819e3e03449b3ae936c1f05a5965e1e3151df45cb2b929539bb7c82b3d5e0062ce2906f2594286d2
Size (checkdmarc-5.15.2.tar.gz) = 64152 bytes
@


1.27
log
@py-checkdmarc: updated to 5.14.1

5.14.1

Fixes

Make the DMARC p tag required again until DMARCbis is released with an RFC number.


5.14.0

DMARCbis changes

New tags: np (non-existent subdomain policy), psd (PSD flag), t (test mode) with descriptions, defaults, and validation

Removed tag warnings: pct, rf, ri descriptions appended with "Removed in DMARCbis." and emit warnings when explicitly present in a record

Optional p tag: Missing p now produces a warning and defaults to none instead of raising an error

"The p tag is optional in DMARCbis, but is required in older versions of DMARC."
DNS tree walk: query_dmarc_record replaces PSL-based get_base_domain lookup with the DMARCbis tree walk algorithm (walks parent domains one label at a time, with 8-label query limit optimization)

Bug fixes

dmarc.py — get_dmarc_tag_description: allowed_values was always {} — never populated from dmarc_tags[tag]["values"], making value-specific descriptions dead code
dmarc.py — _query_dmarc_record: f"The domain {0} does not exist.".format(domain) mixed f-string with .format(), producing "The domain 0 does not exist." regardless of input
mta_sts.py — parse_mta_sts_policy: 4 missing raise keywords — exceptions for duplicate keys, invalid version, invalid mode, and non-integer max_age were instantiated but never raised, silently accepting invalid policies. Also fixed the duplicate key detection which incorrectly used the pre-populated parsed_policy dict (where defaults like max_age: 0 were already present), replaced with a seen_keys set.
smtp_tls_reporting.py — parse_smtp_tls_reporting_record: Missing raise keyword — SMTPTLSReportingSyntaxError for a missing required rua tag was instantiated but never raised, silently allowing records without the required tag.
Tests

92 new unit tests (153 total, up from 61) providing comprehensive coverage across all modules. Overall project test coverage improved from 45% to 58%.

dmarc.py (60% → 82%): Tag descriptions, syntax errors, duplicate/invalid tags, pct edge cases, parked domain warnings, fo/rf/sp tag warnings, report URI parsing, record queries, DNS tree walk, check_dmarc
mta_sts.py (32% → 71%): Record/policy parsing, duplicate keys, invalid version/mode/max_age, missing keys, mx pattern matching
smtp_tls_reporting.py (38% → 69%): Record parsing, tag descriptions, invalid/duplicate tags, missing rua, HTTPS URIs
soa.py (43% → 89%): soa_rname_to_email, parse_soa_string, check_soa
__init__.py (21% → 54%): results_to_json, results_to_csv_rows, check_ns
spf.py (73% → 77%): query_spf_record, check_spf, parked domains, redirect macros, all mechanism variants
dnssec.py (16% → 28%): test_dnssec (mocked), DNSKEY cache
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.26 2026/01/26 20:17:25 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.14.1.tar.gz) = d573de51d259d685da037cf9c85b45e0e39750e2f69262ea8bfc530531488f5d
SHA512 (checkdmarc-5.14.1.tar.gz) = 9b548dc592df822553a8638f7465d90b00520732fe27027dffd06be92f224b0470a6fd64fb300b5ec1d9fffea29b6dac8137d8ddf0dd827a998cfa95d77475c2
Size (checkdmarc-5.14.1.tar.gz) = 63286 bytes
@


1.26
log
@py-checkdmarc: updated to 5.13.3

5.13.3
Fixes
Refactor extract_logo_from_certificate() to improve logo extraction from certificate data
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.25 2026/01/11 10:07:06 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.13.3.tar.gz) = 9b3a1b6625448b899fa8e6b216f732f5c65196304462b4fd108eb64f652ba8f2
SHA512 (checkdmarc-5.13.3.tar.gz) = cbac46d2a9d02e982cc139b20efdc0394816052e8bd225bdff7211e99965cd14e384c14d6558aea6c75b8557cce44768fa3760200177958767af8dada8f6aafc
Size (checkdmarc-5.13.3.tar.gz) = 61990 bytes
@


1.25
log
@py-checkdmarc: updated to 5.13.2

5.13.2
Skip undecodable TXT records instead of raising exception during SPF lookup
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.24 2025/12/30 12:55:13 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.13.2.tar.gz) = 7ea8948fac8d0c6375fe0c4061006674e2b43b6cefce2e1d9991c63ce74d19a0
SHA512 (checkdmarc-5.13.2.tar.gz) = f94fcaf1a1b9ab3425cc2bab6e5f1d202913df09a1831b655b4a97b11635dd5a22d04285c17b5f8c1015e3c970730283eaedeaf6902b099408e80ecc8d10d6d3
Size (checkdmarc-5.13.2.tar.gz) = 61564 bytes
@


1.24
log
@py-checkdmarc: updated to 5.13.1

5.13.1

Fix check_domains return type annotation
Fix Dockerfile COPY destination path
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.23 2025/12/22 06:00:56 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.13.1.tar.gz) = bdab13f88ab2461b3670a2159f0d2b68cd4fe77c1ce26037bd98e0e75c885394
SHA512 (checkdmarc-5.13.1.tar.gz) = 3e789210e0a0804009c819df0b160d8991f04a4eabd3696bb54bdd9e5d2ab5686796e8b0763c3fa87a7e70e2f3dfe481104f08256816c46e3cc48a37beb5bd27
Size (checkdmarc-5.13.1.tar.gz) = 61450 bytes
@


1.23
log
@py-checkdmarc: updated to 5.13.0

5.13.0

Updated dependencies to allow cryptography 46 to be used
fix: dynamically select timeout method to avoid PicklingError on macOS
Rewrite of the SPF module
Remove return statement from the finally block
Retry DNS queries if they time out
Rename caught exception value in spf parsing
Create and use Docker image
bug fixes
Validate DMARC sp tag like p tag
211 spf void lookup miscount
Reject SPF records with concatenated 'all' mechanisms without whitesp…
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.22 2025/12/05 11:28:40 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.13.0.tar.gz) = 1d5118ff898494d7cece25d63ef7a77dc45bf611f77b2a8bcd3c7c769a0bdbfc
SHA512 (checkdmarc-5.13.0.tar.gz) = 6116e39be9ac55611d4bfc73367d7f19f80c8d62f5c5a85dc85ddd56ed45d324176e37b21aab37bf85b3220b0288a80b378f17cb8277773166be1a22a088e0d7
Size (checkdmarc-5.13.0.tar.gz) = 61152 bytes
@


1.22
log
@py-checkdmarc: updated to 5.12.26

5.12.26

Fixes

SPF void miscount
Reject SPF records with an all mechanism that is not preceded by whitespace
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.21 2025/11/12 17:30:26 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.12.26.tar.gz) = 8a7c77295f519dbfd2df1452861c3185b01bfe75d70241b9ed56f0b8eb99c4e6
SHA512 (checkdmarc-5.12.26.tar.gz) = 7beb47208c7b3c108598b8fcee7e75f65056ceeeb527442d1da36b1f311b3a3e543e141de0eb222643ac23251e66828033dffc9eb5f0c4604aeca44a27475531
Size (checkdmarc-5.12.26.tar.gz) = 55108 bytes
@


1.21
log
@py-checkdmarc: updated to 5.12.25

5.12.25

Remove quotes from SPF record output
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.20 2025/10/30 11:40:52 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.12.25.tar.gz) = 8762679c7c200710a30017eb7ff9a5589a300df73bd39f33b0d92a0f6da8f6d9
SHA512 (checkdmarc-5.12.25.tar.gz) = 2780295173fb64a40f6fda9ff078e7eaa38a1db92715f46a66d12a4f4f6d2768e96f9dd530804543fa2d5e845d0ae784d05735dcd277994900a5027d41991755
Size (checkdmarc-5.12.25.tar.gz) = 54441 bytes
@


1.20
log
@py-checkdmarc: updated to 5.12.24

5.12.24

Properly detect SPF records split with quotes
Always show the related domain in SPF warnings
Fix typo in the DMARC record does not exist error message
Use timeout_retries when querying for MX records

5.12.23

Restore constant warning messages without breaking anything

5.12.22

Restore SPFRecordNotFound.__init__() that was accidentally deleted in 5.12.19

5.12.21

Fix typo in the DMARC record does not exist error message

5.12.20

Don't overcount lookups caused by the mx mechanism
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.19 2025/10/03 05:44:49 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.12.24.tar.gz) = 32ff22f962af38b11dc8b3e3a4c97f4d5cc2736bf6908b8b86f67c64bb22021b
SHA512 (checkdmarc-5.12.24.tar.gz) = 0fc9e67c4806a690f8d33442afc1eb4af95ff15f94d05d871623ba01a454b69bff7767953b1e2d8b12b042b4c0a47c5ac3bcc104dcdf75e3860fcb7d68791619
Size (checkdmarc-5.12.24.tar.gz) = 54434 bytes
@


1.19
log
@py-checkdmarc: updated to 5.10.13

5.10.13

Fix macOS multiprocessing compatibility with timeout decorators
Updated dependencies to allow cryptography 46 to be used
Make error messages consistent
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.18 2025/09/22 14:40:31 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.10.13.tar.gz) = d1e851a96a7556e314b88526837ca5ec7c29c62f2c92237a250c21e2c8c5b4e5
SHA512 (checkdmarc-5.10.13.tar.gz) = e6e64513d3cd629595b66b0585dd56113e2d4e026e5739181c570391675465c3a6690a2f5823d2912171950672e1c0ff34a9f6d6ef0721a5c4a37654a4f07319
Size (checkdmarc-5.10.13.tar.gz) = 50935 bytes
@


1.18
log
@py-checkdmarc: updated to 5.10.12

5.10.12
Proper checking for the start of an SPF record
Improve error messages and fix typos
Remove warning when no MX records are found
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.17 2025/09/14 06:52:24 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.10.12.tar.gz) = da8fc050991474c801dbaaebaa82768f39f621ce837da82f54a61f7afbac71e8
SHA512 (checkdmarc-5.10.12.tar.gz) = e29a12c02cf37588fe6dd022b5fb78460b682478e86522ba0d4d36235360ae2de8531f13d66ba48e2ed35a4001d52b763057d3b5e94d388f267278068f3b63d8
Size (checkdmarc-5.10.12.tar.gz) = 50826 bytes
@


1.17
log
@py-checkdmarc: updated to 5.10.10

5.10.10

Add missing periods at the end of BIMI error messages and warnings
5.10.9

Add periods at the end of error messages to make them nicer for web apps
5.10.8

Return the proper error message when checking an SOA record for a domain that exist
5.10.7

Set use_signals=False when using timeout decorator to allow it to be used in multithreaded applications such as web applications
5.10.6

Fix BIMI certificate validation error generation
Add support for the avp bimi tag
5.10.5

Switch from DNS over UDP to DNS over TCP for DNSSEC and TLSA queries
5.10.4

Provide a clearer description of SPF void lookup warnings
5.10.3

Fix: SPF includes are not displayed beyond the 10 lookup limit
Add a warning when a size limit is added to a DMARC report destination
5.10.2

Fix BIMI cert expiration time display
5.10.1

Update the cryptography requirement to work with the BIMI module rewrite
5.10.0

Migrate BIMI certificate checks from pyOpenSSL to pyca/cryptography
Add SOA record parsing
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.16 2025/08/28 10:23:03 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.10.10.tar.gz) = ab3e48b2f580ccc1768062248afb6a6b0f99bbb1dc5a2820348c23cd5c2cb662
SHA512 (checkdmarc-5.10.10.tar.gz) = d20a933a59f20b702fba65808b6d6ebafa6c09bf90e43f44a2f8ab7bb2bb4b9f798c62869265a671d9d5a383d981490bdfbe6b5ce252c1c422aa8b3ca01ff87f
Size (checkdmarc-5.10.10.tar.gz) = 50461 bytes
@


1.16
log
@py-checkdmarc: updated to 5.9.2

5.9.2

Treat square aspect ratio as a recommendation rather than a requirement for BIMI SVG files

5.9.1

Fix BIMI record parsing error introduced in 5.9.0

5.9.0

Bug fixes:

Remove zero-width characters from domain inputs
Add a warning when the DMARC record p or sp value is none
Evaluate DMARC when checking BIMI
Do lot show a BIMI certificate warning when the l tag is set to ""
Include warnings if a domain is using BIMI, but does not have an enforced DMARC policy

New features:

Parsed SPF record details are now provided even if it uses too many DNS lookups

Having all of the details of a SPF record that is over the DNS lookup limit can help administrators see what portions of the SPF record are using the most lookups. The parsed record data can be found in the parsed key. In the event that a domain is over the lookup limit, valid will still be set to false and a helpful message describing the problem can be found in the error key.

API changes:

Require keyword arguments to be passed as keyword=value pairs instead of positional arguments
Add the option ignore_too_many_lookups to checkdmarc.spf.parse_spf_record()
This option will stop checkdmarc.spf.parse_spf_record() from rasing exceptions related to too many DNS lookups, in support of the new feature
False by default to maintain backwards compatibility
checkdmarc.spf.check_spf() uses this functionality to support the new feature
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.15 2025/08/25 17:05:54 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.9.2.tar.gz) = 2c46844a29e790a3feef68abe4e63981eba3785606f690f909a3f9a52b37e4cc
SHA512 (checkdmarc-5.9.2.tar.gz) = 2b50a21b59d1635edb8612b23d4066965b9c35d3f126c9ca8f596c4f546441301158911235e15faf6ac1fa68f10c72ffcdda2cc863bf57a5f7f971412bf400ea
Size (checkdmarc-5.9.2.tar.gz) = 45488 bytes
@


1.15
log
@py-checkdmarc: updated to 5.8.9

5.8.9

Fix error message grammar

5.8.8

Provide an easier to understand error message when a mark certificate is not is not issued by a recognized Mark Verifying Authority (MVA)
Bug fix: failure to download a BIMI image is noted in the certificate section instead of the image section

5.8.7

Fix downloading of mta-sts policies
Fix DMARC policy checks for parked domains/subdomains
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.14 2025/06/05 18:10:29 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.8.9.tar.gz) = 8edd4b540f047fb3996c2f435f480af2a551225f77d8db72e3c8385def462252
SHA512 (checkdmarc-5.8.9.tar.gz) = c0dbe7f71544699b1b47b31d39510b9048ec03989bfffe3081e2cffcbcafac5957346c33ecfe87062945098fa7ddab3e6350c97a5d8d4d115535a73d619efd6b
Size (checkdmarc-5.8.9.tar.gz) = 44578 bytes
@


1.14
log
@py-checkdmarc: updated to 5.8.6

5.8.6

Ignore unhandled critical extensions for mark certificates

5.8.5

Remove Entrust VMC root
Add GlobalSign VMC root

5.8.4

Update JSON output for BIMI
Rename the expires field to not_valid_after
Add not_valid_before field
Add expired boolean field
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.13 2025/05/21 07:01:20 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.8.6.tar.gz) = 6e62c7cb9872a5609998fde997e8d542434adc947889723a8f8485b3e8277fcc
SHA512 (checkdmarc-5.8.6.tar.gz) = 61b0a8a7ccae33eb29bcf03f3f7de5d5ad8a5711367f98d1a79f2628e7271b4803ff1ba1261b4baa924edb804b833396d00d0944f3fb077bf5a68c73b0ab1c8a
Size (checkdmarc-5.8.6.tar.gz) = 44395 bytes
@


1.13
log
@py-checkdmarc: updated to 5.8.3

5.8.3

Use timeout values for HTTP client timeouts

5.8.2

Add SSL.com root VMC CA certificates to MVCCAs.pem
Replace deprecated importlib.resources.path call with importlib.resources.file
Use importlib-resources to support older versions of Python
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.12 2025/03/03 13:04:15 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.8.3.tar.gz) = 64dc637e0cae90cf80577c18c3c3c746df299b3f301fccdc8137d0f35ea1c40d
SHA512 (checkdmarc-5.8.3.tar.gz) = 26816955c4ef84ac8ce229d4ec21ef4eb12c8f6f6bba6bd4f786d9c11f75b05869166defdc65224f00ed5357d73fee87445386ee91f5f654e0756ef74afdf1ae
Size (checkdmarc-5.8.3.tar.gz) = 44250 bytes
@


1.12
log
@py-checkdmarc: updated to 5.8.1

5.8.1
Fix incomplete fix for issue 159
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.11 2025/02/26 10:11:23 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.8.1.tar.gz) = b2ba910a061a20845f671438e0057241c3c37fa2335ce128719a2f5f4796bcb5
SHA512 (checkdmarc-5.8.1.tar.gz) = 2df7856b8837f5edd9682b2d7162b5cfc0c064203aa8e868ebe139449473c557d02cc0e923a0eb28f21bcadbb3d0d517c81d2e2d2f77e00c09d38e81e75c6394
Size (checkdmarc-5.8.1.tar.gz) = 42182 bytes
@


1.11
log
@py-checkdmarc: updated to 5.8.0

5.8.0
Support ra=, rp= and rr= tags from RFC 6652
Do not use static answer positions when checking DNSSEC and TLSA
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.10 2024/12/30 14:33:41 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.8.0.tar.gz) = 27859e298184bc6ad0a6e306bb1d6b5ebe04b7a20b6fd71cff068e00e91f657d
SHA512 (checkdmarc-5.8.0.tar.gz) = 4feb9270a2f2f5e83bd9fc4dcf147b47b40297642770915dd77dd190d35699cdbca900d33123ee8b23e0201535cafa563bd474c864fc36f0a1c13e6729d3fd47
Size (checkdmarc-5.8.0.tar.gz) = 42218 bytes
@


1.10
log
@py-checkdmarc: updated to 5.7.11

5.7.11

5.7.11

Do not replace subdomains with base domains in SPF a mechanisms
5.7.10

Raise a warning instead of a UnicodeDecodeError when encountering a TXT record that is not decodable
Alow CIDR notation on SPF a mechanisms
Fix documentation for check_smtp_tls_reporting
Fix SVG verification checks for BIMI SVG files
Allow BIMI Mark Verification Certificates to be used for subdomains
Fix crash on CSV output for a domain with BIMI errors
Fix generation of API documentation
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.9 2024/11/08 14:17:29 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.7.11.tar.gz) = 38cf66a4ee12321b754c3f7855b36e266c321ca2b24d96fb29d9c14f7db9767b
SHA512 (checkdmarc-5.7.11.tar.gz) = d1f1ce01512a2bdf2384e359d357aec160e0cb8afd16dad085230e1a5280e613ea0118aa2a96958f8006315a8c805b00041f9f25eed37d2eb466b982ce8a5337
Size (checkdmarc-5.7.11.tar.gz) = 41940 bytes
@


1.9
log
@py-checkdmarc: updated to 5.7.9

5.7.9

Add an error message to ["bimi"]["image]["error"] instead of ["bimi"]["warnings"] when a BIMI image download fails
Add an error message to ["bimi"]["certificate]["error"] instead of ["bimi"]["warnings"] when a BIMI certificate download fails

5.7.8

Move SVG validation errors from ["bimi"]["warnings"] to ["bimi"]["image"]["validation_errors"]

5.7.7

Fix VMC validation errors not appearing

5.7.6

Fix crash when trying to output to CSV format
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.8 2024/10/31 10:42:40 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.7.9.tar.gz) = 6c17068395c27c3067a8af2a6335b7abe61cf00b53f7faee8c4f79093629079e
SHA512 (checkdmarc-5.7.9.tar.gz) = d4e0c7ef2dec16d3bc1ab0ece58a965b467ee27a89ab94299745769c76b62e1f26ee453e310c17208530780ff0084e3c046e5971051e144fe3fc3b3b7ddae579
Size (checkdmarc-5.7.9.tar.gz) = 41476 bytes
@


1.8
log
@py-checkdmarc: updated to 5.7.5

5.7.4

Add additional checks for tiny-ps SVG requirements

5.7.3

BIMI images and mark certificates
Better error handling
Simplified warning messages
sha256_hash output tfields renamed to sha256
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.7 2024/10/29 09:50:05 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.7.5.tar.gz) = 387320eb1538f13221aa9b5a2f16bf16cdfbfcbe950fe8553e5a830ef862818e
SHA512 (checkdmarc-5.7.5.tar.gz) = baae2f32c8712ed1adfe38c9c8af61e8ff27292c6604550018a67909c36d07bf0102981d4625b481bb69f092724f1e0cfc2f3a80d543c0d26916e8b9bd21b266
Size (checkdmarc-5.7.5.tar.gz) = 41371 bytes
@


1.7
log
@py-checkdmarc: updated to 5.7.2

5.7.2
Account for float SVG sizes

5.7.1
Properly parse a certificate SAN
Certificate warnings fire properly
Make the expires timestamp more readable
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.6 2024/10/28 20:47:31 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.7.2.tar.gz) = 8de0e37126e760de7cb19b2a930e5092229136fe4fb4a8d2f43afbaab26bf015
SHA512 (checkdmarc-5.7.2.tar.gz) = e7b6009ba3cf8b2edbe5b78f516f222ad7e031e5660089790c41b5efa8f44532318078f19b87e9b35f50853e776a6d54d5e1994006814acb6902c5f8498a8716
Size (checkdmarc-5.7.2.tar.gz) = 41264 bytes
@


1.6
log
@py-checkdmarc: updated to 5.6.2

5.6.2

Add a warning when BIMI records do not provide a mark certificate
Ude the correct dependency (xmltodict, not xml2dict)

5.6.1

Fix SVG base profile detection

5.6.0

Automatically check for a BIMI DNS record at the default selector when using the CLI
Fix parsing of BIMI record tags when they are separated by a ; without a space
Validate the file at the URL in the BIMI l tag value
Must be a SVG file
The SVG version must be 1.2
The SVG base profile must be tiny-ps
The SVG dimensions must be square
The file size must not exceed 32 KB
Note: This does not currently include certificate validation.
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.5 2024/08/20 07:14:11 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.6.2.tar.gz) = fffecbe7e62df9a0382dd68da160338478efa45f1e778fb8a8d9b3a1b4dcb2f9
SHA512 (checkdmarc-5.6.2.tar.gz) = fd318e1ab1327346a3d8d42616716580fa560b9f4340ffca3f2a9f61cc219aa9eed3642cadea33a8b151145be5c454c0f4f0e8bbf8bccfd454be79886c0e27f4
Size (checkdmarc-5.6.2.tar.gz) = 35120 bytes
@


1.5
log
@py-checkdmarc: updated to 5.5.0

5.5.0

Support redirect in SPF
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.4 2024/07/20 06:20:22 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.5.0.tar.gz) = 6d1b7f6c92dd66aaa877fd8aa6eae56dc8a1f67a49482b7ef0b4a0ae9d2bb761
SHA512 (checkdmarc-5.5.0.tar.gz) = 41d0f52aae414643ff1dc717af113b78e8f520db63e59371e6f729f1a04897d1c3bff0d733f748539d00ae7f2935d47c69f950bcee613f39e5188b7e1d6c6cf8
Size (checkdmarc-5.5.0.tar.gz) = 36103 bytes
@


1.4
log
@py-checkdmarc: updated to 5.4.0

5.4.0

Fix TLS/STARTTLS check
Consider tls: true if starttls: true
Handle records not existing if ignoring unrelated records
Query the base domain if a DMARC record is not found at the subdomain
Do not accept include= in the SPF record
Fix DNSSEC cache
Fixed checking whether there is some text after all SPF directive
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.3 2024/02/22 13:12:25 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.4.0.tar.gz) = 9eac6f2c9721be1097fb37fac21abdb24937135c1a227118a34f796ac538130c
SHA512 (checkdmarc-5.4.0.tar.gz) = 12e16ad9713d0e2315ba359fb1aca29e9911b547a6ae01428177aa93b48bd6f160dedb697d6e244b8ad546643c3e08d8cf7ea630f1a4083f20f560511f4d63c7
Size (checkdmarc-5.4.0.tar.gz) = 36074 bytes
@


1.3
log
@py-checkdmarc: updated to 5.3.1

5.3.1

Ignore UnicodeDecodeError exceptions when querying for TXT records
5.3.0

Check DNSSEC on MX hostnames
USE DNSSEC when requesting DNSKEY records
5.2.7

Do not require an RRSIG answer when querying for DNSKEY records
On Windows and macOS, querying for a DNSKEY record on proton.ch will return a RRSET and RRSIG. However, running the same query on Debian-based Linux will only return a RRSET
Pass in nameservers and timeout when running get_dnskey recursively
5.2.6

Revert change introduced in 5.2.4 that caused the DNSSEC test to always return True
Test for multiple RDATA types when testing DNSSEC
Properly cache DNSSEC test results
5.2.5

Properly cache DNSKEY answers
5.2.4

Workaround DNSSEC testing bug in Debian for some domains
On Windows, querying for a DNSKEY record on proton.ch will return a RRSET and RRSIG. However, running the same query on Linux will only return a RRSET, but will return a RRSET and RRSIG if another record type is requested, such as A
5.2.3

Fix exception handling for query_mta_sts_record
Fix exception handling for query_smtp_tls_reporting_record
5.2.2

Better exception handling for query_mta_sts_record
More verbose debug logging
5.2.1

Fix bug where TLSA records would not be checked in some cases
Improved debug logging
5.2.0

Check for TLSA records
5.1.0

Add support for parsing SMTP TLS Reporting (RFC8460) DNS records
5.0.2

Fix DNSSEC test
Add missing import dns.dnssec
Always use the actual subdomain or domain provided
5.0.1

Include MTA-STS and BIMI results in CSV output
Renamed include_dmarc_tag_descriptions parameter in checkdmarc.check_domains() to include_tag_descriptions
Added the include_tag_descriptions parameter to checkdmarc.bimi.check_bimi()
Ignore encoding value when checking the Content-Type header during the MTA-STS policy download
Added the exception class MTASTSPolicyDownloadError
Update documentation
5.0.0

Major refactoring: Change from a single module to a package of modules, with each checked standard as its own package
Add support for MTA-STS RFC 8461
Add support for BIMI
Specify a BIMI selector using the --bimi-selector/-b option
Various bug fixes
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.2 2022/11/30 10:38:49 adam Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-5.3.1.tar.gz) = 725cddefc6351c0a5ad6bcfe9dcb52f148c2d7794bf8f53e150b0ce0d9cb67b6
SHA512 (checkdmarc-5.3.1.tar.gz) = a9ce97c77d3e3d32f0416d994aec84c47fd7d6c130b32d89c2f176da9d7814ab3fae67fc6324a44aee1fcf5be5cd32d27a8c4d678b6a8c9be5ce3378ce166747
Size (checkdmarc-5.3.1.tar.gz) = 36307 bytes
@


1.2
log
@py-checkdmarc: updated to 4.4.5

4.4.4

Fix DNS caching

4.4.3

Fix tarball build

4.4.2

Fix CSV output
Always parse RUA and RUF fields, even if other parts of the record are invalid
Convert documentation to markdown
Migrate build from setuptools to hatch
Migrate automated testing from Travis CI to GitHub Actions
@
text
@d1 1
a1 1
$NetBSD: distinfo,v 1.1 2022/08/24 10:18:34 wiz Exp $
d3 3
a5 3
BLAKE2s (checkdmarc-4.4.5.tar.gz) = f0b57e7427b009cda40a9bda8a57ff4842106db5c570094301f3100252fa44a8
SHA512 (checkdmarc-4.4.5.tar.gz) = 8e59d23fa6cffb68c55bda93f93992fc9e954e38b41ea39f4f8a0e8ec80321536dc31afe144636277c6789aa25c4f084f333599a97eb31fa78b4f02290b11cd6
Size (checkdmarc-4.4.5.tar.gz) = 23975 bytes
@


1.1
log
@mail/py-checkdmarc: import py-checkdmarc-4.4.1

A Python module and command line utility for validating SPF and
DMARC DNS records.
@
text
@d1 1
a1 1
$NetBSD$
d3 3
a5 3
BLAKE2s (checkdmarc-4.4.1.tar.gz) = fb8d7f3631bc7240e60ec3596060ca319fde27a4ae2a4a06b4f78fac80a78840
SHA512 (checkdmarc-4.4.1.tar.gz) = d255387a06a90e9f94301b30dde5c0fbd4d0f36438b81fd2109e3b952a8207b9908bd37507b8adfe19dd9e6446ca3866910891038377af89cda6507d734a3ae4
Size (checkdmarc-4.4.1.tar.gz) = 22930 bytes
@

