Re: A Quickhack

Hadmut Danisch <[email protected]> Sun, 26 Oct 2003 15:03:12 +0100
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
On Sun, Oct 26, 2003 at 08:11:14AM -0500, Richard Rognlie wrote:
> 
> It might tell you that "yes, this host is allowed to be this IP"
> but it says nothing about "this IP is allowed to send mail and 
> claim to be this hostname"
> 

OK, I've thought a little bit about it. We need to discuss it.

- As long as we need to verify the HELO hostname only to keep 
  relaying running that would be broken by MAIL FROM checking
  otherwise, we don't need it, because the A record does the job 
  in my eyes.


- If you want to cover more functionality, i. e. giving the domain 
  admin the opportunity to disallow certain machines to deliver 
  e-mail, then we'd have DRIP (or apply our combined mechanism to 
  the HELO command).

  Where's the advantage over the A record?

  If in a company or university has computers out of control
  which could be used by abusive employees, hijacked or virus 
  infected, it could prevent abusive delivery (if they do not have
  a firewall, which does it anyway).

 

Well, we can do this. But I think we should discuss and decide,
whether we also want to cover this functionality. Until now I was
under the impression that we verify HELO only as a fallback to keep 
forwarding alive. 

If we support it, we should at least have a precise statement why 
we do it.



regards
Hadmut