Re: A Quickhack
Hadmut Danisch <[email protected]> Sun, 26 Oct 2003 15:03:12 +0100
| Newsgroups | gmane.ietf.asrg.rmx |
|---|---|
| Message-ID | <[email protected]> |
On Sun, Oct 26, 2003 at 08:11:14AM -0500, Richard Rognlie wrote: > > It might tell you that "yes, this host is allowed to be this IP" > but it says nothing about "this IP is allowed to send mail and > claim to be this hostname" > OK, I've thought a little bit about it. We need to discuss it. - As long as we need to verify the HELO hostname only to keep relaying running that would be broken by MAIL FROM checking otherwise, we don't need it, because the A record does the job in my eyes. - If you want to cover more functionality, i. e. giving the domain admin the opportunity to disallow certain machines to deliver e-mail, then we'd have DRIP (or apply our combined mechanism to the HELO command). Where's the advantage over the A record? If in a company or university has computers out of control which could be used by abusive employees, hijacked or virus infected, it could prevent abusive delivery (if they do not have a firewall, which does it anyway). Well, we can do this. But I think we should discuss and decide, whether we also want to cover this functionality. Until now I was under the impression that we verify HELO only as a fallback to keep forwarding alive. If we support it, we should at least have a precise statement why we do it. regards Hadmut