Re: SPF isn't going to change, was Deprecating SPF
Hadriel Kaplan <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On Aug 24, 2013, at 12:14 AM, Mark Andrews <[email protected]> wrote: > > In message <[email protected]>, Andrew Sullivan writes: >> I am an SPF validator. On day 0, there are very few people publishing >> SPF-99 records, and many publishing SPF-16 records. I have a lot of >> mail volume coming in. What is my incentive to embrace SPFCheckNG? >> Please address the latency effects for large mail operators. > > Most of the latency should be handled be handled in app / on machine > DNS caches. Add dns hammer support in the caches and almost all > of the rest of the latency is gone. I don't follow that logic. I work for a vendor that makes an MTA. As far as I can tell from publicly-accessible docs, it only does type-16 today. If I were to put myself in a product manager's shoes, I don't see any reason I'd implement a type-99 check. Obviously if type-99 was the *only* RR available from some significant population of domains, we might change our MTA to also do a type-99. But if everyone makes TXT type-16 available in DNS as well, what motivation would we have to do type-99 first, or even at all? Why would we bother with the additional overhead? I mean if you didn't have a type-16 SPF in your DNS, what are the odds you have a type-99? It's not as simple as: "but the code is easy to write". For one thing any functional change in commercial products is far more work and cost than just a developer changing some lines of code. For another, customers don't really care about IETF RFC conformance checklists much - they care about things working. Adding processing or delay overhead has to provide some new real benefit, for them. Pain for no gain makes no sense, to both vendors and their customers. And if major MTA vendors and providers only do type-16 checks, what motivation is there for people to stop putting type-16 in their DNS? You'd want *everyone* to be able to check your domain's SPF, I would think. Not just those querying for type-99. Right? -hadriel disclaimer: this email does not represent Oracle in any way, I am merely speaking as an individual. Oracle products may well do type-99 checking already today, or in the near-future, for all I know. _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext