Re: Forwarders' hopes, was SPF and bouncing
alan <[email protected]> Mon, 09 Apr 2012 12:46:03 +0100
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <[email protected]> |
At 10:21 09/04/2012 Monday, Alessandro Vesely wrote: >On Mon 09/Apr/2012 11:07:16 +0200 alan wrote: >> At 11:01 08/04/2012 Sunday, Alessandro Vesely wrote: >>> >>> What about "generic" forwarders? I mean sites who provide a web-form >>> to let users specify whatever address they like. They are obviously >>> not going to hound ultimate servers' admins in order to have their >>> site whitelisted. BTW, most target domains are gmail, yahoo, and the >>> like, so such whitelisting is probably tantamount a whitelist of all >>> legitimate mail servers, which is probably what those huge mailbox >>> providers are doing anyway. >> >> we do the web form provision, we set envelope sender to >> account-identifier@our-domain (so sfp pass) and bounces to this are >> re-written to the owner of the site site owners who use hotmail or >> gmail are required to setup their hotmail/gmail to pickup their >> mail by pop3 rather than have us forward it to them > >That's the most sensible way to do it, IMHO. From a legal POV, it >enables the forwarder to keep a target address undisclosed, if its >owner so wishes. Bounces going back directly to the original sender >would break such privacy constraint. yeah and as webform forwarding the original sender can be forged, intentionally or typo (its just an entry in a form) so bouncing to that ever would be an avenue for abuse. but I hadn't thought of the anonymity portion before i might just have to add some code to our SRS so that address's in the body of returned bounces get appropriately re-written (obviously these returned bounces being from mailbox full or server down) as other 5xx's cause the admin team to kill the forwarded address >However, I reckon a minority of mail sites do forwarding that way. >Or is that a feature of my Internet's local group? i would say its a minority, as only a minority (in any field) tend to actively try and ensure at design stage that their systems attempt to honour 'do no harm' at every level >>> Small to normally large mail sites cannot be reliable forwarding >>> targets if they reject when an smtp.mailfrom results in a fail. >>> So, I think it would be fair to require to also check smtp.helo in >>> such cases, and accept the message if the it results in a pass. What >>> do you think? >> >> most site owners on small sites have the ability to just whitelist >> their webservers (our servers) sending ip, those that arnt able to >> usually have to setup some sort of pop3 pickup if their mailsystem >> dosnt allow reliable forwarding > >You mean FBL subscriptions? That's the last bullet point in John >Levine's rough summary of forwarding: >http://www.circleid.com/posts/how_spam_has_damaged_mail_forwarding_and_ways_to_get_around_it/ good article. no im not on any FBL as were a tiny sender, but receive for many. (still tiny in global terms) i just mean any user wishing to setup forwarding on an address here to external has to demonstrate the external can either A whitelist mail from our IP to that RCPT (whitelist for content and mail-from checks) as the user scan set both filters on our receiving side and should do no further checking on subsequent hops. B whitelist our ip system-wide (not our preference but often a limitation of many other MTA's/filters) or if they cannot they have to go with pop3 pickup as we won't forward to places that might cause our systems to become back scatter sources >------------------------------------------- >Sender Policy Framework: http://www.openspf.net [http://www.openspf.net] >Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/] > >Archives: https://www.listbox.com/member/archive/735/=now >RSS Feed: https://www.listbox.com/member/archive/rss/735/13124949-0b42f103 >Modify Your Subscription: https://www.listbox.com/member/?& >Unsubscribe Now: https://www.listbox.com/unsubscribe/?&&post_id=20120409052211:7A590F74-8225-11E1-BC0C-E8C87D88F881 >Powered by Listbox: http://www.listbox.com