Re: Forwarders' hopes, was SPF and bouncing

Alessandro Vesely <[email protected]> Mon, 09 Apr 2012 11:21:54 +0200
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
On Mon 09/Apr/2012 11:07:16 +0200 alan wrote:
> At 11:01 08/04/2012  Sunday, Alessandro Vesely wrote:
>>
>> What about "generic" forwarders?  I mean sites who provide a web-form
>> to let users specify whatever address they like.  They are obviously
>> not going to hound ultimate servers' admins in order to have their
>> site whitelisted.  BTW, most target domains are gmail, yahoo, and the
>> like, so such whitelisting is probably tantamount a whitelist of all
>> legitimate mail servers, which is probably what those huge mailbox
>> providers are doing anyway.
> 
> we do the web form provision, we set envelope sender to
> account-identifier@our-domain (so sfp pass) and bounces to this are
> re-written to the owner of the site site owners who use hotmail or
> gmail are required to setup their hotmail/gmail to pickup their
> mail by pop3 rather than have us forward it to them

That's the most sensible way to do it, IMHO.  From a legal POV, it
enables the forwarder to keep a target address undisclosed, if its
owner so wishes.  Bounces going back directly to the original sender
would break such privacy constraint.

However, I reckon a minority of mail sites do forwarding that way.
Or is that a feature of my Internet's local group?

>> Small to normally large mail sites cannot be reliable forwarding
>> targets if they reject when an smtp.mailfrom results in a fail.
>> So, I think it would be fair to require to also check smtp.helo in
>> such cases, and accept the message if the it results in a pass.  What
>> do you think?
> 
> most site owners on small sites have the ability to just whitelist
> their webservers (our servers) sending ip, those that arnt able to
> usually have to setup some sort of pop3 pickup if their mailsystem
> dosnt allow reliable forwarding

You mean FBL subscriptions?  That's the last bullet point in John
Levine's rough summary of forwarding:
http://www.circleid.com/posts/how_spam_has_damaged_mail_forwarding_and_ways_to_get_around_it/