Re: Not! the same DNS records for different checks

Hadmut Danisch <[email protected]> Sun, 26 Oct 2003 20:59:21 +0100
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
On Sun, Oct 26, 2003 at 02:46:42PM -0500, Raymond S Brand wrote:
> 
> How does this tell you that the hostname is authorized to relay mail?


Well, until now I did not see that this is a desirable goal to be
achieved.


I was under the assumption that there is only one authorization step, 
the authorization be the sender address domain. If this is impossible
(odd forwarding, empty sender address), then I thought that it is
desired to see which domain the sending machine belongs to in order to 
allow later blaming.

I was not aware that we want to provide an additional authorization by
the owner of the domain where the HELO name belongs to, which means
that there are two distinct kinds of machines in this domain,
authorized ones and those, which belong to the domain but are not
authorized. 

I understand that DRIP copes with this problem, but I was and am 
not aware that we actually do have this problem and do want to solve
this problem. I actually don't know of any network at the moment which
would want to have such records (because they use firewalls or simply
do not want to restrict it).


Don't get me wrong, I do not object. I'm still uncertain that this 
solves a problem that we have to solve and is of real use. Convince
me.

regards
Hadmut