Re: Not! the same DNS records for different checks
Hadmut Danisch <[email protected]> Sun, 26 Oct 2003 20:59:21 +0100
| Newsgroups | gmane.ietf.asrg.rmx |
|---|---|
| Message-ID | <[email protected]> |
On Sun, Oct 26, 2003 at 02:46:42PM -0500, Raymond S Brand wrote: > > How does this tell you that the hostname is authorized to relay mail? Well, until now I did not see that this is a desirable goal to be achieved. I was under the assumption that there is only one authorization step, the authorization be the sender address domain. If this is impossible (odd forwarding, empty sender address), then I thought that it is desired to see which domain the sending machine belongs to in order to allow later blaming. I was not aware that we want to provide an additional authorization by the owner of the domain where the HELO name belongs to, which means that there are two distinct kinds of machines in this domain, authorized ones and those, which belong to the domain but are not authorized. I understand that DRIP copes with this problem, but I was and am not aware that we actually do have this problem and do want to solve this problem. I actually don't know of any network at the moment which would want to have such records (because they use firewalls or simply do not want to restrict it). Don't get me wrong, I do not object. I'm still uncertain that this solves a problem that we have to solve and is of real use. Convince me. regards Hadmut