SPF

"Ian Peter" <[email protected]> Mon, 23 Feb 2004 08:07:20 +1000
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAAir8oDSM7nEeU6yNQVTbmpcKAAAAQAAAAJpH4o3Fq3kaD66ZkDCxu9AEAAAAA@ianpeter.com>
(re-sent with title changed)


> -----Original Message-----
> From: [email protected]
[mailto:[email protected]]
> On Behalf Of Ian Peter
> Sent: Monday, 23 February 2004 7:28 AM
> To: 'Patrik Fältström'
> Cc: 'Yakov Shafranovich'; [email protected]
> Subject: Re: static versus dynamic nature of DNS: rate limiting
>
> What’s clear to me is that major benefit will come from some sort of
> smtp verification scheme being adopted widely, be it lmap or spf or
some
> other variation. What's also clear to me is that we need to act
quickly
> to restore some sort of faith in email as a medium.
>
> I wonder if its possible before the IETF meeting to have at least a
> brief exchange as regards SPF. SPF has gained quite a degree of
> momentum, and in my mind at least it's best to back winners in
> situations like this and put some of the other issues aside.
>
> Let's leave aside issues of who thought of it first and whether it's
> proper form to start an initiative like this outside of asrg/ietf, and
> concentrate only on the technical merits of SPF.
>
> We have a good prototype. Does it have major flaws? Are they solvable
or
> unsolvable? Is it worthwhile this group putting its efforts behind
SPF?
>
>
>
> Ian Peter
> Ian Peter and Associates Pty Ltd
> P.O. Box 10670 Adelaide St
> Brisbane 4000 Australia
> Tel 61 7 3870 1181
> Mobile 0419 667772
>
> > -----Original Message-----
> > From: [email protected]
> [mailto:[email protected]]
> > On Behalf Of Patrik Fältström
> > Sent: Monday, 23 February 2004 6:28 AM
> > To: Hadmut Danisch
> > Cc: Yakov Shafranovich; [email protected]
> > Subject: Re: static versus dynamic nature of DNS: rate limiting
> >
> > On 2004-02-22, at 21.19, Hadmut Danisch wrote:
> >
> > > On Sun, Feb 22, 2004 at 09:06:34PM +0100, Patrik Fältström wrote:
> > >>
> > >> - Given a mail is coming from a peer which the domain owner the
> mail
> > >> comes from approves, there are legal and policing mechanisms
which
> can
> > >> take over
> > >
> > > Are you sure?
> > >
> > > I do know a lot of countries where nobody would care about
> > > spammers. Countries which don't put drug dealers into prison
> > > won't certainly have strong legal mechanisms against spammers.
> > >
> > > Maybe you will have such mechanisms in the USA, but how will you
> > > know whom to sue if you don't know who sent the fedex envelope to
> > > lease a domain?
> >
> > First of all, I live in Sweden, not the US.
> >
> > Secondly, I said "can" and meant to use the word to mean "it is then
> > possible to...". Not that it always will happen.
> >
> > But, for example, just see the drastic changes in the EU the last
> year,
> > and similar reactions in the US.
> >
> > The idea is to create a trail which can be followed. If the
> authorities
> > go to a domain name seller to ask "who owns this domain name", and
> they
> > can not answer? What do you think the next law will be? Of course
> > people will be forced to know this in the future, or _they_ (the
> > registrar) will be the one doing the wrong things. Or, with help of
> > some whois it will be possible to say "no, I will not trust any
domain
> > name which is registered by this registry" etc.
> >
> > All of these things are possible to do in a much better way when
"we"
> > have minimized the risk for false sender addresses, so tracing the
> > source is easier.
> >
> > We need to go down this path.
> >
> >      paf