Re: misconception in SPF
Christian Grunfeld <[email protected]>
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <CAFdugamTbTirVV2zXKOmc9oTaCS+QiTemhT=jvYJnHYscHQK7g@mail.gmail.com> |
2012/12/9 Dave Crocker <[email protected]>: > Strange thread. Mostly seems to be based on using SPF in ways that it is > not designed to be used. It's always problematic to criticize a technology > for failing to provide services that it is not intended to provide. > An essential point, above, is worrying about "semi-tech-savvy people". > First, SPF is not for end-users. It is for receive-side operators and their > filtering engines. When operators believes that SPF and their filtering engines are well configurated but a forged email pass anyway (by means of this thread), it finally reaches a "semi-tech-savvy user" who is more trusting of Twitter mail coming from 'bibble.twitter.com' than if it came from 'random.ru'. None of us are saying that simple users deals with SPF directly ! > Second, embedded technologies, like SPF, cannot be mail fool-proof against > poor use by operators who misunderstand one or another aspect of the > technology. Better software and better documentation are the best one can > do for them. yes, this is a misunderstanding and I believe this is a good place to discuss, isn't it?....but I think is a misunderstanding of a huge part of the operators..excluding you of course !