Re: misconception in SPF

Christian Grunfeld <[email protected]>
Newsgroups gmane.ietf.asrg
Message-ID <CAFduga=KOu-PeRrz3GmDFC77OoeKBTQTNPmP6NwicvY+VUmjVA@mail.gmail.com>
2012/12/6 Martijn Grooten <[email protected]>:

> You could also use aimport dot no (as some spammer sending a fake Twitter email did an hour ago). That domain doesn't have an SPF record either.

simple users are more confident if the sender seems real !

> As we're talking about the MAIL FROM in the SMTP envelope, which usually isn't shown to the user, I don't think this is a big problem.

faking From: header is as simple as faking MAIL FROM envelope !

> Perhaps your MTA or spam-filter does use the MAIL FROM in its decision whether to deliver the email or not. If it decides to deliver the message because it claims to come from Twitter, uses a subdomain of twitter.com and didn't fail SPF than that's very wrong. But I don't think it's SPF's fault.

I didn't say is SPF's fault. It's our fault
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.