Re: Forwarders' hopes, was SPF and bouncing

alan <[email protected]> Mon, 09 Apr 2012 12:46:03 +0100
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
At 10:21 09/04/2012  Monday, Alessandro Vesely wrote:
>On Mon 09/Apr/2012 11:07:16 +0200 alan wrote:
>> At 11:01 08/04/2012  Sunday, Alessandro Vesely wrote:
>>>
>>> What about "generic" forwarders?  I mean sites who provide a web-form
>>> to let users specify whatever address they like.  They are obviously
>>> not going to hound ultimate servers' admins in order to have their
>>> site whitelisted.  BTW, most target domains are gmail, yahoo, and the
>>> like, so such whitelisting is probably tantamount a whitelist of all
>>> legitimate mail servers, which is probably what those huge mailbox
>>> providers are doing anyway.
>> 
>> we do the web form provision, we set envelope sender to
>> account-identifier@our-domain (so sfp pass) and bounces to this are
>> re-written to the owner of the site site owners who use hotmail or
>> gmail are required to setup their hotmail/gmail to pickup their
>> mail by pop3 rather than have us forward it to them
>
>That's the most sensible way to do it, IMHO.  From a legal POV, it
>enables the forwarder to keep a target address undisclosed, if its
>owner so wishes.  Bounces going back directly to the original sender
>would break such privacy constraint.

yeah and as webform forwarding the original sender can be forged, intentionally or typo (its just an entry in a form) so bouncing to that ever would be an avenue for abuse.

but I hadn't thought of the anonymity portion before i might just have to add some code to our SRS so that address's in the body of returned bounces get appropriately re-written (obviously these returned bounces being from mailbox full or server down)  as other 5xx's cause the admin team to kill the forwarded address

>However, I reckon a minority of mail sites do forwarding that way.
>Or is that a feature of my Internet's local group?

i would say its a minority, as only a minority (in any field) tend to actively try and ensure at design stage that their systems attempt to honour 'do no harm' at every level 

>>> Small to normally large mail sites cannot be reliable forwarding
>>> targets if they reject when an smtp.mailfrom results in a fail.
>>> So, I think it would be fair to require to also check smtp.helo in
>>> such cases, and accept the message if the it results in a pass.  What
>>> do you think?
>> 
>> most site owners on small sites have the ability to just whitelist
>> their webservers (our servers) sending ip, those that arnt able to
>> usually have to setup some sort of pop3 pickup if their mailsystem
>> dosnt allow reliable forwarding
>
>You mean FBL subscriptions?  That's the last bullet point in John
>Levine's rough summary of forwarding:
>http://www.circleid.com/posts/how_spam_has_damaged_mail_forwarding_and_ways_to_get_around_it/

good article.
no im not on any FBL as were a tiny sender, but receive for many. (still tiny in global terms)
i just mean any user wishing to setup forwarding on an address here to external has to demonstrate the external can either

A whitelist mail from our IP to that RCPT (whitelist for content and mail-from checks) as the user scan set both filters on our receiving side and should do no further checking on subsequent hops.
B whitelist our ip system-wide (not our preference but often a limitation of many other MTA's/filters)
or if they cannot they have to go with pop3 pickup as we won't forward to places that might cause our systems to become back scatter sources




>-------------------------------------------
>Sender Policy Framework: http://www.openspf.net [http://www.openspf.net]
>Modify Your Subscription: http://www.listbox.com/member/ [http://www.listbox.com/member/]
>
>Archives: https://www.listbox.com/member/archive/735/=now
>RSS Feed: https://www.listbox.com/member/archive/rss/735/13124949-0b42f103
>Modify Your Subscription: https://www.listbox.com/member/?&
>Unsubscribe Now: https://www.listbox.com/unsubscribe/?&&post_id=20120409052211:7A590F74-8225-11E1-BC0C-E8C87D88F881
>Powered by Listbox: http://www.listbox.com