Re: Email Web of Trust - Problem Statement

Yakov Shafranovich <[email protected]> Mon, 08 Mar 2004 20:36:20 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
Peter J. Holzer wrote:
> On 2004-03-08 17:21:34 -0500, Yakov Shafranovich wrote:
...
>>>More generally, the trust could be based on a particular policy or set
>>>of policies:  A particular domain, for example, might be trusted to
>>>adhere to certain antispam policies regarding UBE, authenticating
>>>senders, responding to complaints, etc.
>>>
>>>I think we need to resolve this question before discussing mechanisms.
>>>
>>
>>I was actually thinking of whether a specific domain is trusted to
>>provide non-forged data in SMTP, staying away from the definitions of spam.
> 
> 
> How do you determine that? It is relatively simple to get an opinion
> (either from a user or a program like SpamAssassin) on whether a given
> message is spam or not. But whether the return-path is forged or not is
> an objective criterium which can not easily be verified. If you get a
> message from <[email protected]> from the MTA 143.130.50.112, is that
> forged or not?
> 

Isn't the whole point of a trust system is to provide a way to verify 
something via a vouching mechanism rather than relying on a test by 
SpamAssasin or a user?

Yakov