RE: SPF and bouncing

"Murray S. Kucherawy" <[email protected]> Fri, 6 Apr 2012 14:12:48 +0000
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <9452079D1A51524AA5749AD23E0039280CCCB0@exch-mbx901.corp.cloudmark.com>
> -----Original Message-----
> From: G.W. Haywood [mailto:[email protected]]
> Sent: Friday, April 06, 2012 3:46 AM
> To: SPF discuss
> Subject: Re: [spf-discuss] SPF and bouncing
> 
> > "Is it okay, on the modern internet, to send a bounce message outside
> > of one's own bailiwick, when the original message had an SPF Pass
> > result?"
> 
> One simple answer.  No.
> 
> I really can't see why the thread has trundled on for so long.

Sure it is.  Anyone can reject a message for any of a variety of policy reasons regardless of what SPF says.

The problem to me is the ambiguity of the question.

> Incidentally I see more spammers (far more, both in absolute terms and
> as a proportion) than genuine mail senders using SPF, and the senders
> of genuine mail screw up their SPF records far more often and in more
> imaginative ways than the spammers do.  It almost drives me to despair.

For the work of the spfbis working group at IETF, I just ran a survey of over a quarter million domains' SPF records.  Some of the errors are indeed quite creative, not to mention the junk a parser has to deal with along the way.  For example, do a TXT query for any of these:

B93radio.com
Wncy.com
Wtaq.com
Dealdirectsendz.info
Ut.edu
Aaronline.com
Dwgsecurity.com
Emergogroup.com
Banctec.com
Warwick.ac.uk

Those are just my top ten by record count.

-MSK