Re: SPF and bouncing
Michael Deutschmann <[email protected]> Mon, 7 May 2012 04:41:45 -0700 (PDT)
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <%[email protected]> |
On Mon, 7 May 2012, Alessandro Vesely wrote: > You seem to imply that messages bearing a null-mailfrom must be > bounces. Actually, it is the opposite way around: bounces must bear a > null-mailfrom. Null-mailfrom traffic other than DSNs is insignificant. IMAO, it's ok to break it. > > Drop the "is equal to or a subdomain" requirement, and any spammer who > > wants to exploit the <> loophole will do so using a HELO domain that he > > fully owns. Then it's trivial for him to engineer a genuine SPF Pass. > > It is equally trivial to engineer such a pass using MFROM. Not if you need to pass a goldlist at the same time. If the spammer uses a MAIL FROM within a domain he fully controls, he can pass SPF with flying colors, but gets 5xxed anyway because the goldlist has never heard of him. If he uses the MAIL FROM of an actual correspondent of the victim, he passes the goldlist but now cannot cheese past SPF. ---- Michael Deutschmann <[email protected]>