Re: Problems with SPF, solutions, and a timeline.
Meng Weng Wong <[email protected]> Sat, 28 Feb 2004 02:14:51 -0500
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
On Sat, Feb 28, 2004 at 02:24:37AM -0000, John Levine wrote: | | I would argue that the biggest weakness of all the LMAP systems is | that the domain they test, the one in the envelope bounce address, | isn't one that means anything to recipients. If I were a bad guy, I'd | register some throwaway domains, or I'd forge some badly managed | third-world domains with no LMAP data, use them in the bounce address | to pass LMAP checks, and forge like crazy in the From: and Sender: | lines that people see. That's fine by me as long as I stop getting the bounce messages. | Another issue is one-way mail domains like Meng's pobox.com. They can | publish SPF data saying mail's OK from anywhere, which is like a "kick | me" sign inviting spammers to forge it, or you can demand that the sender | use the real address of the place where he sends it, which has privacy | problems, or you can try some SRS like hack. Actually, for the past three years we've offered SMTP AUTH on 587 to all our users, and now we're going to try to start chivvying them towards it. Of course, they are perfectly free to ignore that; if they want to set up per-user SPF records, they are welcome to set that up too. We will start protecting individual users; users can always opt out and remain in "kick me" status.