Re: Spamming...

"Chris Haynes" <[email protected]> Thu, 28 Apr 2005 15:16:34 +0100
Newsgroups gmane.mail.im2000
Message-ID <04c101c54bfc$e2541450$0600000a@john>
 "Brian Candler" replied, in part:

> On Thu, Apr 28, 2005 at 12:25:43PM +0100, Chris Haynes wrote:
>> Here's where we differ.  It's the people whose domains are forged (e.g.
>> 'joe-job' victims) who have every incentive to publish SPF.
>
> However to have any effect, it requires:
> (1) you to publish SPF policies for your domain in the DNS; and
> (2) lots of other people across the Internet to respect your SPF policies.
>
> By implementing SPF on your own servers, you are benefiting other people on
> the Internet (i.e. those who publish SPF policies), and not yourself. You
> may argue that you are protecting yourself against spam with forged senders;
> however I read an article which claims that spam is *more* SPF compliant
> that E-mail in general.
>
>...

The proposition that SPF was primarily intended for spam reduction was 
deprecated long ago.  Its focus is detecting forgery of origin.

It's generally regarded as 'a good thing' if spammers adopt SFP, because then 
you can probably trace them via their DNS registration and can hold them 
accountable. Either they can be traced or their domain registrar can held 
accountable for registering unverifiable domain owners.

SPF also provides you with a more stable 'identity' for use in reputation 
systems, black lists, etc. That's where SPF can form part of a spam-reduction 
regime.

Chris Haynes