Re: Patches from Robert Millan

Julian Mehnle <[email protected]>
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Robert Millan wrote:
> On Fri, Jul 13, 2007 at 11:25:26PM +0000, Julian Mehnle wrote:
> > > Adding the Null Mail From HELO check is useful.  The approach used
> > > here is consistent with the approach that many long standing SPF
> > > libraries (Mail::SPF::Query and pyspf for two) take.  So this is
> > > good.
> >
> > Agreed.  (Do not construe this as a retreat from the newer Mail::SPF
> > Perl module's more formal approach, whose author I am.  Whereas I
> > prefer the more formal approach, the less formal one used by
> > Mail::SPF::Query, pyspf, and now libspf2, is certainly legitimate.)
>
> What is the other approach?

Mail::SPF's approach is more formal in that it does not automatically
switch over to checking the HELO identity in case of the MAIL FROM identity
being empty.  Rather, there is only one identity argument (not "mfrom" +
"helo"), and Mail::SPF requires you to check for yourself whether MAIL FROM
is empty and then pass the HELO identity to make a "postmaster@<HELO>"
check.  (Note in particular that RFC 4408 does not require implementations
to automate this.  I think it's cleaner if they don't.)

See <http://search.cpan.org/dist/Mail-SPF/lib/Mail/SPF/Request.pm#mfrom>
and <http://search.cpan.org/dist/Mail-SPF/lib/Mail/SPF/Request.pm#identity>.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGmNCJwL7PKlBZWjsRAtnTAKDxDxJotgP6Pi9Q7Buzypi7c4Xj0ACg8z2s
PvEa/tyFpVwDFUvQ0EIOrCI=
=KX+o
-----END PGP SIGNATURE-----

-------------------------------------------
-----------------------------------------------------------------------
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=6959932&id_secret=22117513-08e291
Powered by Listbox: http://www.listbox.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.