Re: SPF and bouncing

Alessandro Vesely <[email protected]> Fri, 04 May 2012 20:45:33 +0200
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
On Fri 04/May/2012 20:20:10 +0200 Scott Kitterman wrote:
> On Friday, May 04, 2012 05:12:14 AM Michael Deutschmann wrote:
>> To avoid spammers using "MAIL FROM: <>" as a "skeleton key" that opens
>> all the mailboxes, a whitelisting site would have to use VERP such as
>> BATV.  But automatic whitelisting fails when other people VERP in the
>> same way.  We have a sustainability problem.
> 
> The way that SPF attempts to deal with null mail from now is with HELO based 
> checks.  These are arguably far less useful.

Why?

> Spammers have not adapted to SPF by moving to null mail from's.

That's a well known recipe to get your message rejected, see
http://www.rfc-ignorant.org/policy-dsn.php

I wonder whether reject-on-fail is statistically more relevant than
reject-null-mailfrom.  In any case, from a spammer's POV, it makes
sense to try and avoid both of those pitfalls at the same time.