Re: SPF and bouncing

alan <[email protected]> Wed, 04 Apr 2012 12:34:07 +0100
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
At 08:19 04/04/2012  Wednesday, Michael Deutschmann wrote:
>On Tue, 3 Apr 2012, Stuart D. Gathman wrote:
>> Well, if you still needed proof that alias forwarding is broken, there
>> you have it.  Those that will not accept SPF end up banning DSNs instead.
>
>I don't see how "accepting SPF" can help save bounces or forwarders.  SPF
>is certainly an annoyance to forwarders.
>
>At present, SPF is nowhere near deployed enough (senderside) for it to be
>viable to refuse all mail not bearing an SPF Pass or <>. 

its not an OR equation mail from <> still has an spf result based on the helo of the connecting server

either way people still have to accept spf neutral mail froms and <>

(<> is used for more than bounces if you bother to look)

>Since the Conspiracy Against Bouncing has decreed that lack of SPF information is
>not an excuse to emit backscatter,

spf has nothing to do with backscatter (spf allows those guilty of creating backscatter to reduce their volume by /dev/nulling the backscatter they would generate IF the original mail failed SPF)
either way those generating backscatter should instead fix their mailsystems and thus eliminate the problem (instead of wasting time with volume reduction stratagies involving spf/dkim etc) 

>that means that mailservers have to be prepared to accept unbounceable mail.

the opposite they should accept or reject at their edge, once the decision is made though they should not later change their minds.

>If SPF deployment did rise to that level, the past experience with the
>conspiracy will make actual bounces rather rare.

what conspiracy?? what agenda do you have? those of us wanting properly run mailsystems use all technologies and methods to make the ecosystem sustainable, this includes engineering our own systems to prevent any avenue of abuse (such as emitting backscatter), we educate others by shunning those that emit abuse ala open-relay RBLs and how they eliminated the common and abusive practice of open relays, noways we track and shun those that emit backscatter by blocking <> from those known to emit it through simmilar RBLs. and the use of BATV
(not through blocking all <>)
same as we policy block mail from known spammers,known compromised systems, known open relays, and for many people systems known to not police their systems adequately to prevent their users forgeries.
(receiver system receivers rules, i side with the educators in my policies but my users can choose their own policy for their address')

>At the same time, spammers will be tempted to use the <> sender to save the trouble of
>making throwaway domains.

thats a truely dumb argument.
A no spammers currently do this, what they do is send the spam to a backscatter emitting system from<victim> to non-existant and rely on the backscatter emitting system to create and send the 'bounce-spam' backscatter from<> to <victim>
B no submission server (run well) accepts mail from <> thus no one can create a mail from <>
C no one in their right mind accepts direct to MX spam thus not accepting forged <> or forged <real-user>
D the issue for well run systems is finding and educating through shunning, spammers-run mailservers, backscatter emitters, badly setup submission servers (ones that allow senders to forge the from) which allow A,B or straight forged spam

>So spamfilters will block all attempts to use <>; thus bouncing will still be unusable.

anyone that does this is patently a moron (and thus deserves the issues rejecting bounces causes for their users never knowing their mail was undelivered)
if worried about forged <> 
BATV is a simple and easily implemented way to reject forged bounces 


>---- Michael Deutschmann <[email protected]>
>
>
>-------------------------------------------
>Sender Policy Framework: http://www.openspf.net [http://www.openspf.net]
>Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]
>
>Archives: https://www.listbox.com/member/archive/735/=now
>RSS Feed: https://www.listbox.com/member/archive/rss/735/13124949-0b42f103
>Modify Your Subscription: https://www.listbox.com/member/?&
>Unsubscribe Now: https://www.listbox.com/unsubscribe/?&&post_id=20120404031951:8F83D990-7E26-11E1-AEE1-D8D3A91823E1
>Powered by Listbox: http://www.listbox.com