Problems with SPF, solutions, and a timeline.

Meng Weng Wong <[email protected]> Fri, 27 Feb 2004 18:16:22 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On Mon, Feb 23, 2004 at 08:07:20AM +1000, Ian Peter wrote:
| >
| > We have a good prototype. Does it have major flaws? Are they solvable or
| > unsolvable? Is it worthwhile this group putting its efforts behind SPF?

The major flaws of any designated-sender LMAP proposal are that they
break forwarding and web-generated email.  We have know this for some
time, and we have been working on solutions.  The solution the SPF
community is pushing is called SRS, for Sender Rewriting Scheme.

SRS is maturing rapidly and is approaching a deployable form.  Libraries
have been written in Perl and C.  Patches to MTAs are becoming available.

http://spf.pobox.com/intro.html#breakage links to a slideshow that
explains the issues.  http://spf.pobox.com/srs.html talks more about
SRS.

If the technical problem can be solved, the remaining challenge is
outreach and education, and that's a much bigger problem.  It needs a
different set of tools.

We need to persuade forwarding service providers and the web-generated
email sites that their energy should go toward upgrades and
compatibility rather than fighting sender authentication.

And that is where the IETF can really use its authority to good effect.

Depending on how things go in Seoul, it may be feasible to agree on a
project timeline for testing, implementation, and deployment that can be
ratified by a critical mass of industry leaders together with the IETF.

I think it is entirely within the realm of possibility to see all the
large organizational forwarding providers performing rewriting by the
end of July.  If the MTA community is willing to play along, they should
be shipping SRS-enabled versions by then.  Web-generated email sites
should follow that schedule also.

Once those initial obstacles are out of the way, SPF adoption can proceed
quickly.  SPF adopters won't have to worry about the bogeyman of
forwarding.

The next big obstacle is that ISPs need educating and users need
reconfiguring for SMTP AUTH.  When the Port 587 BCP comes out that will
be a big step forward.

Throughout this conversion process, I believe the best way to encourage
the process is to give everybody a common schedule to work toward.

cheers
meng