Re: Problems with SPF, solutions, and a timeline.

John Levine <[email protected]> 28 Feb 2004 02:24:37 -0000
Newsgroups gmane.ietf.asrg.smtpverify
Organization I.E.C.C., Trumansburg NY USA
Message-ID <[email protected]>
>| > We have a good prototype. Does it have major flaws? Are they solvable or
>| > unsolvable? Is it worthwhile this group putting its efforts behind SPF?
>
>The major flaws of any designated-sender LMAP proposal are that they
>break forwarding and web-generated email.

I would argue that the biggest weakness of all the LMAP systems is
that the domain they test, the one in the envelope bounce address,
isn't one that means anything to recipients.  If I were a bad guy, I'd
register some throwaway domains, or I'd forge some badly managed
third-world domains with no LMAP data, use them in the bounce address
to pass LMAP checks, and forge like crazy in the From: and Sender:
lines that people see.

This is a fundamental problem not amenable to band-aids.  Demanding
that the From: and envelope addresses match is out of the question,
since it would break every mailing list in the world.

Another issue is one-way mail domains like Meng's pobox.com.  They can
publish SPF data saying mail's OK from anywhere, which is like a "kick
me" sign inviting spammers to forge it, or you can demand that the sender
use the real address of the place where he sends it, which has privacy
problems, or you can try some SRS like hack.

The first problem is the biggest, whether preventing envelope forgery
will in practice deter spammers.  If not, the whole LMAP exercise is
pointless.





-- 
John R. Levine, IECC, POB 727, Trumansburg NY 14886 +1 607 330 5711
[email protected], Village Trustee and Sewer Commissioner, http://iecc.com/johnl, 
Member, Provisional board, Coalition Against Unsolicited Commercial E-mail