Re: [spf-help] Re: SPF and SenderID

John Leslie <[email protected]> Fri, 22 Jul 2005 07:43:42 -0400
Newsgroups gmane.ietf.mxcomp
Message-ID <20050722114342.GB666@verdi>
Alan DeKok <[email protected]> wrote:
> John Leslie <[email protected]> wrote:
> 
>> I read Kjetil's argument to be that with SPF, your reputation will
>> not quickly recover, and will inhibit email "From" your domain for
>> quite a while,
> 
> I'm not sure why that is, as the explanation wasn't clear to me.
> Nothing in CSV or SPF that I can see indicates how quickly reputation
> will recover.  So assertions that reputation will recover more quickly
> for one than the other are unwarranted.

   Agreed. The essential argument has been that CSV's reputation is
more granular: it's the reputation of the MTA (or group of MTAs)
which will suffer, not the reputation of the domain listed in the
"From" address. Thus, you don't need to wait for the reputation to
recover: you can simply change MTAs to one with a good reputation.

> The confusion here is that there are multiple domains that may be
> used for authorization.  EHLO, and MAIL FROM.  When CSV uses EHLO,
> sending "MAIL FROM" a particular domain is invisible to CSV, because
> it's not looking at MAIL FROM.  And in that case, reputation is tied
> to MTA, not to the "MAIL FROM" domain.

   Exactly.

> If CSV uses "MAIL FROM" for reputation, then it has pretty much the
> same issue as any other proposal using that field.

   CSV never pays any attention to MAIL-FROM.

--
John Leslie <[email protected]>