Re: Problems with spf testsuite and dns specification

"Stuart D. Gathman" <[email protected]>
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
On Tue, 12 Jun 2007, Stefano Bagnara wrote:

> > Nevertheless, the SPF spec says that when there are multiple TXT
> > records beginning with "v=spf1", then the correct result is PermError.  
> 
> That's what I'm trying to fix.  IMHO it is correct when the records are
> different, but when they are identical it is a matter of what DNS server
> (servers) and what dns clients are in the resolution chain to know if
> you will receive one or multiple identical records. The SPF spec should
> not rely on this: the DNS spec does not allow such distinction to be
> made and SPF is a DNS based protocol.

If some client library *did*, however, return multiple identical records,
then the correct result is PermError.  Your problem is that when testing
through a live DNS server, it is difficult to reproduce this situation.

Here are some possible resolutions:

1) tag selected tests as "optional for live DNS testing".

2) Add multiple results for tests with multiple identical records.
   There is certainly no ambiguity in using one of 2 duplicate SPF
   records, so implementations can be considered justified in bending the
   current spec a little for this case.

3) Add an errata for the spec addressing the case of duplicate records.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.

-------------------------------------------
-----------------------------------------------------------------------
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=6959932&user_secret=62b4c45f
Powered by Listbox: http://www.listbox.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.