SPF
"Ian Peter" <[email protected]> Mon, 23 Feb 2004 08:07:20 +1000
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAAir8oDSM7nEeU6yNQVTbmpcKAAAAQAAAAJpH4o3Fq3kaD66ZkDCxu9AEAAAAA@ianpeter.com> |
(re-sent with title changed) > -----Original Message----- > From: [email protected] [mailto:[email protected]] > On Behalf Of Ian Peter > Sent: Monday, 23 February 2004 7:28 AM > To: 'Patrik Fältström' > Cc: 'Yakov Shafranovich'; [email protected] > Subject: Re: static versus dynamic nature of DNS: rate limiting > > WhatÂs clear to me is that major benefit will come from some sort of > smtp verification scheme being adopted widely, be it lmap or spf or some > other variation. What's also clear to me is that we need to act quickly > to restore some sort of faith in email as a medium. > > I wonder if its possible before the IETF meeting to have at least a > brief exchange as regards SPF. SPF has gained quite a degree of > momentum, and in my mind at least it's best to back winners in > situations like this and put some of the other issues aside. > > Let's leave aside issues of who thought of it first and whether it's > proper form to start an initiative like this outside of asrg/ietf, and > concentrate only on the technical merits of SPF. > > We have a good prototype. Does it have major flaws? Are they solvable or > unsolvable? Is it worthwhile this group putting its efforts behind SPF? > > > > Ian Peter > Ian Peter and Associates Pty Ltd > P.O. Box 10670 Adelaide St > Brisbane 4000 Australia > Tel 61 7 3870 1181 > Mobile 0419 667772 > > > -----Original Message----- > > From: [email protected] > [mailto:[email protected]] > > On Behalf Of Patrik Fältström > > Sent: Monday, 23 February 2004 6:28 AM > > To: Hadmut Danisch > > Cc: Yakov Shafranovich; [email protected] > > Subject: Re: static versus dynamic nature of DNS: rate limiting > > > > On 2004-02-22, at 21.19, Hadmut Danisch wrote: > > > > > On Sun, Feb 22, 2004 at 09:06:34PM +0100, Patrik Fältström wrote: > > >> > > >> - Given a mail is coming from a peer which the domain owner the > mail > > >> comes from approves, there are legal and policing mechanisms which > can > > >> take over > > > > > > Are you sure? > > > > > > I do know a lot of countries where nobody would care about > > > spammers. Countries which don't put drug dealers into prison > > > won't certainly have strong legal mechanisms against spammers. > > > > > > Maybe you will have such mechanisms in the USA, but how will you > > > know whom to sue if you don't know who sent the fedex envelope to > > > lease a domain? > > > > First of all, I live in Sweden, not the US. > > > > Secondly, I said "can" and meant to use the word to mean "it is then > > possible to...". Not that it always will happen. > > > > But, for example, just see the drastic changes in the EU the last > year, > > and similar reactions in the US. > > > > The idea is to create a trail which can be followed. If the > authorities > > go to a domain name seller to ask "who owns this domain name", and > they > > can not answer? What do you think the next law will be? Of course > > people will be forced to know this in the future, or _they_ (the > > registrar) will be the one doing the wrong things. Or, with help of > > some whois it will be possible to say "no, I will not trust any domain > > name which is registered by this registry" etc. > > > > All of these things are possible to do in a much better way when "we" > > have minimized the risk for false sender addresses, so tracing the > > source is easier. > > > > We need to go down this path. > > > > paf