Re: Malformed Received-SPF header

Sam Varshavchik <[email protected]> Sat, 15 Mar 2025 20:48:15 -0400
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
Bernd Wurst writes:

> Hi,
>
> a customer pointed me to the fact that SpamAssassin's SPF module does not  
> fully understand Courier's Received-SPF header.
>
> Courier sets multiple Received-SPF headers, one for every SPF check it  
> makes. The records are marked with the flag "SPF=HELO" or "SPF=MAILFROM".  
> This is a non standard extension to this header field.
>
> But RFC 4408 does indeed have a flag for the same information. It's called  
> identity=helo or identity=mailfrom.
>
> Could you please add the standard header flag to this header so that the  
> spam filter can understand the provided information?

That's reasonable enough, despite RFC 4408's status that "it does not  
specify an Internet standard of any kind". Par for the course, I suppose.  
This change obviously causes a problem for anything that expects Courier's  
current header format, obviously, but "it does not specify an Internet  
standard of any kind" cuts both ways, here.

I was curious about the history here, and looked into it. Courier's SPF  
implementation predates RFC 4408, and it was based on an earlier draft. Back  
then, I suppose, not much care was given about any existing implementations,  
before RFC 4408 was published.

_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQRupkKLJP96aW75pIOKYPgoojZS4gUCZ9YfzwAKCRCKYPgoojZS
4mNhAP9MR3oxpNCZkNhosl6jAacsQvf/AWUqfY8bIc0xddYHkwEA8ify9vSCWT1q
iXnaaqPne0VpKmLqKJKZ/u64bspglAs=
=fZCN
-----END PGP SIGNATURE-----