Re: SPF and bouncing

Michael Deutschmann <[email protected]> Fri, 6 Apr 2012 21:21:58 -0700 (PDT)
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <%[email protected]>
On Fri, 6 Apr 2012, G.W. Haywood wrote:
> On Tue, 3 Apr 2012, Michael Deutschmann wrote:
> > "Is it okay, on the modern internet, to send a bounce message outside
> >  of one's own bailiwick, when the original message had an SPF Pass
> >  result?"
>
> One simple answer.  No.

How about this variation:

"Is it okay, on the modern internet, to assume that legitimate bounce
messages between bailiwicks will not occur?"

That is, to declare that deadletters other people experience when they try
to bounce something you *actually sent* are their own fault for not
saluting the Conspiracy Against Bouncing.

I'm suprised how vehement people are behind the No regarding the first
question, but that may just be Postel's Law talking. ("Be conservative in
what you send, liberal in what you accept.") Postel would also say No to
the second one.

And on reflection, it's the second question that is most important.  Some
anti-spam strategies become far weaker if asked to treat a bounce message
for failed delivery to <x@y> just as well as a normal message from <x@y>.

Most dramatically, this applies to goldlisting, where any envelope sender
not on the whitelist is rejected.  If <> is not whitelisted, no bounce ever
gets through.  If <> is, anyone from any IP can circumvent the goldlist.

(One idea is to use SPF-checked HELO and/or rDNS to at least get a domain
that can be coarsely checked against the whitelist.  But that can easily
fail, especially if the sending IP is a smarthost for many domains.)

---- Michael Deutschmann <[email protected]>