Re: SPF isn't going to change, was Deprecating SPF

Hadriel Kaplan <[email protected]>
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
On Aug 24, 2013, at 12:14 AM, Mark Andrews <[email protected]> wrote:

> 
> In message <[email protected]>, Andrew Sullivan writes:
>> I am an SPF validator.  On day 0, there are very few people publishing
>> SPF-99 records, and many publishing SPF-16 records.  I have a lot of
>> mail volume coming in.  What is my incentive to embrace SPFCheckNG?
>> Please address the latency effects for large mail operators.
> 
> Most of the latency should be handled be handled in app / on machine
> DNS caches.  Add dns hammer support in the caches and almost all
> of the rest of the latency is gone.


I don't follow that logic.  I work for a vendor that makes an MTA.  As far as I can tell from publicly-accessible docs, it only does type-16 today.

If I were to put myself in a product manager's shoes, I don't see any reason I'd implement a type-99 check.  Obviously if type-99 was the *only* RR available from some significant population of domains, we might change our MTA to also do a type-99.  But if everyone makes TXT type-16 available in DNS as well, what motivation would we have to do type-99 first, or even at all?  Why would we bother with the additional overhead?  I mean if you didn't have a type-16 SPF in your DNS, what are the odds you have a type-99?

It's not as simple as: "but the code is easy to write".  For one thing any functional change in commercial products is far more work and cost than just a developer changing some lines of code.  For another, customers don't really care about IETF RFC conformance checklists much - they care about things working.  Adding processing or delay overhead has to provide some new real benefit, for them.  Pain for no gain makes no sense, to both vendors and their customers.

And if major MTA vendors and providers only do type-16 checks, what motivation is there for people to stop putting type-16 in their DNS?  You'd want *everyone* to be able to check your domain's SPF, I would think.  Not just those querying for type-99.  Right?

-hadriel
disclaimer: this email does not represent Oracle in any way, I am merely speaking as an individual.  Oracle products may well do type-99 checking already today, or in the near-future, for all I know.


_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.