Re: Problems with SPF, solutions, and a timeline.
John Levine <[email protected]> 28 Feb 2004 02:24:37 -0000
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Organization | I.E.C.C., Trumansburg NY USA |
| Message-ID | <[email protected]> |
>| > We have a good prototype. Does it have major flaws? Are they solvable or >| > unsolvable? Is it worthwhile this group putting its efforts behind SPF? > >The major flaws of any designated-sender LMAP proposal are that they >break forwarding and web-generated email. I would argue that the biggest weakness of all the LMAP systems is that the domain they test, the one in the envelope bounce address, isn't one that means anything to recipients. If I were a bad guy, I'd register some throwaway domains, or I'd forge some badly managed third-world domains with no LMAP data, use them in the bounce address to pass LMAP checks, and forge like crazy in the From: and Sender: lines that people see. This is a fundamental problem not amenable to band-aids. Demanding that the From: and envelope addresses match is out of the question, since it would break every mailing list in the world. Another issue is one-way mail domains like Meng's pobox.com. They can publish SPF data saying mail's OK from anywhere, which is like a "kick me" sign inviting spammers to forge it, or you can demand that the sender use the real address of the place where he sends it, which has privacy problems, or you can try some SRS like hack. The first problem is the biggest, whether preventing envelope forgery will in practice deter spammers. If not, the whole LMAP exercise is pointless. -- John R. Levine, IECC, POB 727, Trumansburg NY 14886 +1 607 330 5711 [email protected], Village Trustee and Sewer Commissioner, http://iecc.com/johnl, Member, Provisional board, Coalition Against Unsolicited Commercial E-mail