Re: static versus dynamic nature of DNS: rate limiting

"Ian Peter" <[email protected]> Mon, 23 Feb 2004 07:28:16 +1000
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAAir8oDSM7nEeU6yNQVTbmpcKAAAAQAAAACYC7wkiuJUC+cdh1zWuvIQEAAAAA@ianpeter.com>
What’s clear to me is that major benefit will come from some sort of
smtp verification scheme being adopted widely, be it lmap or spf or some
other variation. What's also clear to me is that we need to act quickly
to restore some sort of faith in email as a medium.

I wonder if its possible before the IETF meeting to have at least a
brief exchange as regards SPF. SPF has gained quite a degree of
momentum, and in my mind at least it's best to back winners in
situations like this and put some of the other issues aside.

Let's leave aside issues of who thought of it first and whether it's
proper form to start an initiative like this outside of asrg/ietf, and
concentrate only on the technical merits of SPF.

We have a good prototype. Does it have major flaws? Are they solvable or
unsolvable? Is it worthwhile this group putting its efforts behind SPF?



Ian Peter
Ian Peter and Associates Pty Ltd
P.O. Box 10670 Adelaide St
Brisbane 4000 Australia
Tel 61 7 3870 1181
Mobile 0419 667772

> -----Original Message-----
> From: [email protected]
[mailto:[email protected]]
> On Behalf Of Patrik Fältström
> Sent: Monday, 23 February 2004 6:28 AM
> To: Hadmut Danisch
> Cc: Yakov Shafranovich; [email protected]
> Subject: Re: static versus dynamic nature of DNS: rate limiting
>
> On 2004-02-22, at 21.19, Hadmut Danisch wrote:
>
> > On Sun, Feb 22, 2004 at 09:06:34PM +0100, Patrik Fältström wrote:
> >>
> >> - Given a mail is coming from a peer which the domain owner the
mail
> >> comes from approves, there are legal and policing mechanisms which
can
> >> take over
> >
> > Are you sure?
> >
> > I do know a lot of countries where nobody would care about
> > spammers. Countries which don't put drug dealers into prison
> > won't certainly have strong legal mechanisms against spammers.
> >
> > Maybe you will have such mechanisms in the USA, but how will you
> > know whom to sue if you don't know who sent the fedex envelope to
> > lease a domain?
>
> First of all, I live in Sweden, not the US.
>
> Secondly, I said "can" and meant to use the word to mean "it is then
> possible to...". Not that it always will happen.
>
> But, for example, just see the drastic changes in the EU the last
year,
> and similar reactions in the US.
>
> The idea is to create a trail which can be followed. If the
authorities
> go to a domain name seller to ask "who owns this domain name", and
they
> can not answer? What do you think the next law will be? Of course
> people will be forced to know this in the future, or _they_ (the
> registrar) will be the one doing the wrong things. Or, with help of
> some whois it will be possible to say "no, I will not trust any domain
> name which is registered by this registry" etc.
>
> All of these things are possible to do in a much better way when "we"
> have minimized the risk for false sender addresses, so tracing the
> source is easier.
>
> We need to go down this path.
>
>      paf