Re: "Last Call" pending exp= (empty) erratum

Julian Mehnle <[email protected]> Thu, 22 Nov 2007 00:29:05 +0000
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Frank Ellermann wrote:
> Scott Kitterman wrote:
> > pyspf 2.0.4 returns Permanent Error: Empty domain-spec on exp=
>
> Thanks, Scott and Julian.  IOW "running code" does not support
> "option 1" for this wannabe erratum.  Maybe that also helps to sort out
> "option 2" vs. "option 3", example policy:
>
> "v=spf1 a -all exp=%{h}" after a FAIL, with a macro-expression yielding
> an empty or otherwise unusable <target-name>, do you report FAIL, or do
> you report an error for the <target-name> ?

%{h} can never yield an empty <target-name>.

Generally, RFC 4408 6.2/4 requires errors in _evaluating_ (not parsing) 
the "exp=" modifier to be ignored as if the modifier was absent:

| If domain-spec is empty, or there are any DNS processing errors (any
| RCODE other than 0), or if no records are returned, or if more than one
| record is returned, or if there are syntax errors in the explanation
| string, then proceed as if no exp modifier was given.

So RFC 4408 implies a result of "Fail" for the above example of yours, and 
this is what Mail::SPF does.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHRM1SwL7PKlBZWjsRApvoAKCMPkAPOQLJSNJ8g7TgS1liyiwoVwCeJ76f
i8l+ceDMVv5NT6RNTprfGvA=
=gTpf
-----END PGP SIGNATURE-----

-------------------------------------------
-----------------------------------------------------------------------
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=6959932&id_secret=67800680-cbac18
Powered by Listbox: http://www.listbox.com