Re: Scope of SMTP Verify

William Leibzon <[email protected]> Wed, 3 Mar 2004 11:22:59 -0800 (PST)
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <Pine.LNX.4.44.0403031058530.21123-100000@cwhois1.completewhois.com>
On Wed, 3 Mar 2004, Alan DeKok wrote:
>   None of this is new.

I did not say its new. In fact this topic was just recently mentioned on 
nanog as well (there is some support for it) and the ideas are probably 4 
years if not more. As I said, it might be good idea to work on this futher
and combine all these proposals and create one description of the system 
(i.e like LMAP document) and thereafter work out technical details allowing
for different records such SPF tried when combining RMX and DMP.

I'm just trying to focus you people as I'm getting rather tired of seeing 
anti-spammers endlessly fighting each other (for whatever reasons) and 
not getting much done, please try to focus on things that are productive 
and have some realistic possibility of nearterm deployment (i.e. not 
requirying change to SMTP as most of my ideas unfortunetly would). 
This qualifies as in my view we highier potential to decrease spam (from 
zombies) a lot more then LMAP would (see my other comments and John 
Levine's but please do not bring this topic up for discussion again)
with no serious negative consequence except possibly mobile linux users 
who would not be able to send email throudh dialup isp directly to somebody
elses server and would have to use authenticate and relay through ISP's 
mail server.

> William Leibzon <[email protected]> wrote:
> > While I do not 
> > particularly like LMAP, it does seem that if this is adopted the same or
> > very simiilar syntax can be used to add records to reverse dns IN-ADDR zones
> > Things you may want to indicate there include:
> > 1. If the ip (or ip block) can be source of SMTP traffic or not. Possibly 
> >    even more specifically on what authentication is to be used (i.e. AUTH, 
> >    STARTTLS)
> 
>   That's pretty much the MTA-MARK proposal.
> 
> > 2. What domain(s) can be used for envelope from when email is being sent 
> >    from that ip (negative consequence: spammer can also see this record 
> >    and may well choose to forge emails as coming from that domain)
> 
>   Not if that domain also publishes LMAP records.
> 
>   That was my proposal from last week, and it neatly solves the
> biggest objection to LMAP.
> 
> > 3. If ip is particular to certain server or user, the record may indicate
> >    public key and all legitimate emails sent from that PCs should then 
> >    have been signed by private key associated with that public key
> 
>   Which is pretty much the DK proposal.
> 
>   None of this is new.
> 
>   Alan DeKok.
>