Re: SPFv3 proposal: rawfail result

"Stuart D. Gathman" <[email protected]>
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
On Sun, 6 Feb 2011, Michael Deutschmann wrote:

> On Sat, 5 Feb 2011, Stuart D. Gathman wrote:
> > The whitelisting is robust for most alias forwarders when you whitelist the
> > forwarder domain, and use SPF or best guess to identify mail from the
> > forwarder.  When attempting the explain this before, I called it
> > a "pretend" MAIL FROM.  The algorithm in its simple form goes like this:
> 
> That doesn't help with the scenario that worries me:
> 
> A user subscribes to ISP A for some time, but then switches to ISP B.
> ISP A graciously sets up a forward from his old mailbox to his new one at
> ISP B (this is also the situation where the forwarder is least motivated
> to try something like SRS).
> 
> ISP B and the user are quite hip mail-security wise, so they arrange a
> whitelisting for the servers ISP A has been using for the handoff, and
> then enable reject-on-SPF-fail for other cases.

You missed the part where you whitelist the DOMAIN, not server IPs.  Using
SPF or best guess if that is not available.

> Then ISP C buys out ISP A, and consolidates mail handling at one data
> center.  The forwards now come from a different IP, different rDNS domain,
> and different HELO.  The whitelisting breaks.

Doesn't break if the SPF record is properly transitioned.  You're right
though that "best guess" would probably break.  That is why we promote SPF.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.