Re: SPF and bouncing

Scott Kitterman <[email protected]> Fri, 04 May 2012 14:54:30 -0400
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <1708397.ja90GQpAPn@scott-latitude-e6320>
On Friday, May 04, 2012 08:45:33 PM Alessandro Vesely wrote:
> On Fri 04/May/2012 20:20:10 +0200 Scott Kitterman wrote:
> > On Friday, May 04, 2012 05:12:14 AM Michael Deutschmann wrote:
> >> To avoid spammers using "MAIL FROM: <>" as a "skeleton key" that opens
> >> all the mailboxes, a whitelisting site would have to use VERP such as
> >> BATV.  But automatic whitelisting fails when other people VERP in the
> >> same way.  We have a sustainability problem.
> > 
> > The way that SPF attempts to deal with null mail from now is with HELO
> > based checks.  These are arguably far less useful.
> 
> Why?

Because the HELO name can be anything, so arranging for an SPF HELO pass is 
trivial.

> > Spammers have not adapted to SPF by moving to null mail from's.
> 
> That's a well known recipe to get your message rejected, see
> http://www.rfc-ignorant.org/policy-dsn.php
> 
> I wonder whether reject-on-fail is statistically more relevant than
> reject-null-mailfrom.  In any case, from a spammer's POV, it makes
> sense to try and avoid both of those pitfalls at the same time.

True.  So maybe SPF just shouldn't care about that case.  No Mail From, not 
our problem.

Scott K