Re: Post-IPocalyptic SPF

"Stuart D. Gathman" <[email protected]>
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
On Sun, 6 Mar 2011, Michael Deutschmann wrote:

> Another approach is a flag to require a TLS certificate.  This has the
> advantage over DKIM of allowing forged connections to be rejected at
> RCPT or earlier -- DKIM must go to DATA to be inspected.  But it would
> only help with NAT/PAT sharing, not with actual smarthosts.

I like that idea.  Stays within the SMTP envelope domain that SPF covers,
and makes sending email from a NAT connection able to be authenticated.
Would the modifer specify the domain expected in the TLS certificate?

Is this what you are thinking?

v=spf1 ?a:mail.6to4.com tls=smtp.example.com -all

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.