Re: SPF and bouncing

Stuart D Gathman <[email protected]> Fri, 20 Apr 2012 23:24:01 -0400
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
Long ago, Nostradamus foresaw that on 04/05/2012 07:56 AM, alan would
write:
>
> again rejecting any mail is acceptable, bouncing (which is accepting and then later returning it to sender) is not ever acceptable, thus SPF isn't a factor in bounce/do not bounce decision, as bounce is never a valid option. 
>
> (simply put receivers should never generate bounces, senders (who can react to the "dead letters" by checking who submitted the forged mail and tightening their own controls on "their" inputs (the cause of the issue) can/should/do generate bounces ONLY)
>
I have no trouble with backscatter, because I "sign" MFROM for outgoing
mail, and forged bounces are rejected at RCPT TO.  This also plays
nicely with Call back validation, since forged emails will not have a
valid MFROM.  It doesn't play as nicely with greylisting, but works ok
as long as signatures don't change too often for a given user.