Re: SPF isn't going to change, was Deprecating SPF
Mark Andrews <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
In message <[email protected]>, Andrew Sullivan writes: > On Fri, Aug 23, 2013 at 06:40:05PM -0700, David Conrad wrote: > > > As far as I can tell, the issue isn't whether the SPF RR is being > > used (it appears to be, albeit at a tiny percentage relative to TXT > > currently) > > Right, despite the fact that 4408 actually suggested that it'd be good > to use SPF. > > > , rather it's whether or not a handful of major mail > > service providers will use SPF RRs in the future if the IETF were to > > document a fix to the broken transition strategy in 4408. > > How would the IETF do that? You say MUST query for SPF and if there is a NO DATA response you MAY query for TXT. Modern spf libraries already do this. Legacy SPF checkers are no longer compliant. Even checkers running under Windows can meet this MUST. You say that nameservers SHOULD synthesis SPF records from TXT v=spf1 records. This helps registrars stuck with broken web interfaces. Code for this is written. You say that nameservers SHOULD reject loading of zones without SPF records when there are v=spf1 TXT records. This provides education for everybody else. Code for this is written. You make all the examples use SPF not TXT. Again more education. You set a sunset date for the use of TXT for spf lookups. > The strategy in 4408 was roughly, "Try > both," though admittedly in a flawed way. But this is exactly the nut > of the problem. There is no way to create an incentive, given the > actual world we live in, for anyone either to publish or to check 99 > as the primary mechanism. As long as 16 is what everyone is already > doing, network effects say that 16 wins. There is no advantage to > anyone in moving to 99: neither on the check side nor on the publish > side do you win. So nobody will. > We either need something new that will make SPF worth doing -- call it > SPF v3 that expresses new policy that's even better (and I can think > of something! Think of EAI-using domains that need better > granularity!) -- or else we need to embrace the lowest common > denominator. Nobody in any of this has offered the slightest > incentive to anyone, AFAICT, except, "DNS is better this way." Who > cares? I do, you do, but we don't organize the universe. > > The above is my claim: nobody cares about this hygiene. If I'm wrong, > then I want a rigourous study to show it, because none of the > empirical evidence suggests so far that accepting and documenting the > facts as they are today is different than the effects of saying, "You > oughta like TYPE99 more." We don't have legislative power. > > A > > -- > Andrew Sullivan > [email protected] > _______________________________________________ > dnsext mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/dnsext -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: [email protected] _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext