RE: CBV

"Stuart D. Gathman" <[email protected]>
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Sun, 16 May 2004, Tony Finch wrote:

> > To validate a message, a recipient does CBV with either
> > a MAIL FROM of <> or a MAIL FROM selected from the message envelope
> > recipients.

> It is often the case that none of the original recipients are available.

If you are not one of the recipients, then you certainly don't want
the mail - unless you have arranged for it to be forwarded by
some outfit that doesn't do SRS, in which case you would have
the appropriate whitelist.

SES/SESR doesn't break sender forwarding (e.g. the hospital
sending baby pictures with your email as MAIL FROM).  Although spam filters
will likely look askance at an unauthenticated sender.  With cryptographic
validation, you could put the hash secret on your Palm Pilot (or Zaurus
or whatever) and have it give you a valid SES/SESR sender address
for use with sender forwarders.

> > Existing practice is to use <> as the MAIL FROM for CBV (is this
> > true?)
> 
> Postfix does callouts using postmaster@.... in the reverse path.

Then this would need to be a special case: treat postmaster@... identically
to <>.

> > If we send something other than <> in the MAIL FROM for a CBV to an MTA
> > that has never heard of this idea, will the CBV still work as intended?

> Not necessarily. The MTA may reject non-bounces to sender-only addresses.

Then we would need to flag SESR and send only plain <> for plain SES.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flamis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.