Re: Post-IPocalyptic SPF
"Stuart D. Gathman" <[email protected]>
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 6 Mar 2011, Michael Deutschmann wrote: > Another approach is a flag to require a TLS certificate. This has the > advantage over DKIM of allowing forged connections to be rejected at > RCPT or earlier -- DKIM must go to DATA to be inspected. But it would > only help with NAT/PAT sharing, not with actual smarthosts. I like that idea. Stays within the SMTP envelope domain that SPF covers, and makes sending email from a NAT connection able to be authenticated. Would the modifer specify the domain expected in the TLS certificate? Is this what you are thinking? v=spf1 ?a:mail.6to4.com tls=smtp.example.com -all -- Stuart D. Gathman <[email protected]> Business Management Systems Inc. Phone: 703 591-0911 Fax: 703 591-6154 "Confutatis maledictis, flammis acribus addictis" - background song for a Microsoft sponsored "Where do you want to go from here?" commercial.