Re: HELO vs. MAIL FROM

Raymond S Brand <[email protected]> Thu, 23 Oct 2003 14:18:43 -0400
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
Gordon Fecyk - Home wrote:
> 
> > Two questions:
> >
> > - Where do we look for RMX/SPF/DRIP/DMP? Do we look at the full
> >   hostname or do we cut off the hostname?
> 
> >   Do we search in the DNS zone of sklave3.rackland.de or
> >   rackland.de? Or do we rekursively descend until we have
> >   2 (or 3 for e.g.  co.uk or com.au) remaining domain components?
> 
> I'd stick with the FQDN, which is what DRIP does from what I've read.
> 
> > - Verifying the EHLO name only _is_ an open door for spamming. It
> >   does allow identification, but not blocking.
> 
> You could still send spam through any MAIL FROM checking too.  But in both
> cases you know who to blame.
> 
> It does allow interesting things like tagging the e-mail.  Any client that
> can filter based on headers can sift through things that fail MAIL FROM but
> pass HELO/EHLO.  Putting the choice back in the recipients' hands.

We have a winner!!

> This approach would offer a worst case which works with everything but
> catches fewer forgeries, and offer an upper level of verification that would
> catch more forgeries while risking lost legit e-mail.  And yes, let the
> recipients or the receiving domain admins decide - it's their property.

Any proposal that ignores this just isn't going be used.

The common feature in all of the proposals is that the domain owner indicates
what is authorized and the receiving MTAs/relays do whatever enforcement they
choose.


Raymond S Brand