Re: Patches from Robert Millan
Julian Mehnle <[email protected]>
| Newsgroups | gmane.mail.spam.spf.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Robert Millan wrote: > On Fri, Jul 13, 2007 at 11:25:26PM +0000, Julian Mehnle wrote: > > > Adding the Null Mail From HELO check is useful. The approach used > > > here is consistent with the approach that many long standing SPF > > > libraries (Mail::SPF::Query and pyspf for two) take. So this is > > > good. > > > > Agreed. (Do not construe this as a retreat from the newer Mail::SPF > > Perl module's more formal approach, whose author I am. Whereas I > > prefer the more formal approach, the less formal one used by > > Mail::SPF::Query, pyspf, and now libspf2, is certainly legitimate.) > > What is the other approach? Mail::SPF's approach is more formal in that it does not automatically switch over to checking the HELO identity in case of the MAIL FROM identity being empty. Rather, there is only one identity argument (not "mfrom" + "helo"), and Mail::SPF requires you to check for yourself whether MAIL FROM is empty and then pass the HELO identity to make a "postmaster@<HELO>" check. (Note in particular that RFC 4408 does not require implementations to automate this. I think it's cleaner if they don't.) See <http://search.cpan.org/dist/Mail-SPF/lib/Mail/SPF/Request.pm#mfrom> and <http://search.cpan.org/dist/Mail-SPF/lib/Mail/SPF/Request.pm#identity>. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGmNCJwL7PKlBZWjsRAtnTAKDxDxJotgP6Pi9Q7Buzypi7c4Xj0ACg8z2s PvEa/tyFpVwDFUvQ0EIOrCI= =KX+o -----END PGP SIGNATURE----- ------------------------------------------- ----------------------------------------------------------------------- To unsubscribe, change your address, or temporarily deactivate your subscription, please go to http://v2.listbox.com/member/?member_id=6959932&id_secret=22117513-08e291 Powered by Listbox: http://www.listbox.com