Re: Why SRS really sucks

"Stuart D. Gathman" <[email protected]> Sun, 26 Mar 2006 21:27:03 -0500 (EST)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Mon, 27 Mar 2006, Johann Steigenberger wrote:

> 1.  SRS makes a good thing as SPF really useless.

> Investigating this, we found, that those providers do not even check for
> SPF-Records and are accepting such crap, but then they are forwarding it with
> SRS !!!

This shows that these "well know providers" are providing the equivalent
of an open-relay - and you should treat them as such.  (But you
have a better idea below.)

> 2. SRS is absolute unnecessary.

You are mostly correct on that score. 

> I need no SRS for this if i really want my mail to get forwardet.
> I only have to use my brian while setting my SPF-record

*And*, SPF checkers need to use their brain and not reject mail
from forwarders that they as a receiver have set up.

> 3. What is my personal suggestion?
> 
> Implementing SPF in software is cool (we also did it), but it  really 
> sucks if you also implement SRS (we will never do it - not in this life !!!)
> 
> Furthermore we implemented in our default ruleset to block every mail which
> is identified to have an SRS envelope from.
> 
> Why ?
> 
> We consider anyone, who thinks he can ignore the domain owners restriction
> as abuser.

This is a reasonable policy - except for one very important thing.
While SRS for forwarding is only needed for braindead SPF recipients,
SRS is *very* useful for "signing" MFROM to eliminate "bounce spam" -
spam with an empty mail from that is not a bounce of anything you sent
(even though that was not the original purpose of SRS).

You can tell when SRS is used in this mode because the two domains are the
same - or else the original domain is empty.

> I recommend to stop SRS, before more people and providers beginn fooling
> around with this nonsense.

The premise of the 'block SRS' policy is that SRS should never be
used for "outgoing" mail from a domain.  It should only be used to 
deliver forwarded mail.  Therefore, if you receive an SRS MFROM 
that is 

a) not a signature (both domains same or one empty)

and 

b) not from a forwarder that you as a receiver have configured

then it is spam and should be rejected.


Anyone see a problem with these assumptions?  Is SRS ever legitimate
for anything other than receiver requested forwarding or MFROM signing?

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.