RE: HELO vs. MAIL FROM

"Gordon Fecyk - Home" <[email protected]> Wed, 22 Oct 2003 22:18:23 -0500
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
> Two questions:
>
> - Where do we look for RMX/SPF/DRIP/DMP? Do we look at the full
>   hostname or do we cut off the hostname?

>   Do we search in the DNS zone of sklave3.rackland.de or
>   rackland.de? Or do we rekursively descend until we have
>   2 (or 3 for e.g.  co.uk or com.au) remaining domain components?

I'd stick with the FQDN, which is what DRIP does from what I've read.

> - Verifying the EHLO name only _is_ an open door for spamming. It
>   does allow identification, but not blocking.

You could still send spam through any MAIL FROM checking too.  But in both
cases you know who to blame.

It does allow interesting things like tagging the e-mail.  Any client that
can filter based on headers can sift through things that fail MAIL FROM but
pass HELO/EHLO.  Putting the choice back in the recipients' hands.

This approach would offer a worst case which works with everything but
catches fewer forgeries, and offer an upper level of verification that would
catch more forgeries while risking lost legit e-mail.  And yes, let the
recipients or the receiving domain admins decide - it's their property.

--
PGP key (0x0AFA039E): <http://www.pan-am.ca/[email protected]>
What's a PGP Key?  See <http://www.pan-am.ca/free.html>
GOD BLESS AMER, er, THE INTERNET. <http://vmyths.com/rant.cfm?id=401&page=4>