Re: Why SRS really sucks
"Stuart D. Gathman" <[email protected]> Sun, 26 Mar 2006 21:27:03 -0500 (EST)
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 27 Mar 2006, Johann Steigenberger wrote: > 1. SRS makes a good thing as SPF really useless. > Investigating this, we found, that those providers do not even check for > SPF-Records and are accepting such crap, but then they are forwarding it with > SRS !!! This shows that these "well know providers" are providing the equivalent of an open-relay - and you should treat them as such. (But you have a better idea below.) > 2. SRS is absolute unnecessary. You are mostly correct on that score. > I need no SRS for this if i really want my mail to get forwardet. > I only have to use my brian while setting my SPF-record *And*, SPF checkers need to use their brain and not reject mail from forwarders that they as a receiver have set up. > 3. What is my personal suggestion? > > Implementing SPF in software is cool (we also did it), but it really > sucks if you also implement SRS (we will never do it - not in this life !!!) > > Furthermore we implemented in our default ruleset to block every mail which > is identified to have an SRS envelope from. > > Why ? > > We consider anyone, who thinks he can ignore the domain owners restriction > as abuser. This is a reasonable policy - except for one very important thing. While SRS for forwarding is only needed for braindead SPF recipients, SRS is *very* useful for "signing" MFROM to eliminate "bounce spam" - spam with an empty mail from that is not a bounce of anything you sent (even though that was not the original purpose of SRS). You can tell when SRS is used in this mode because the two domains are the same - or else the original domain is empty. > I recommend to stop SRS, before more people and providers beginn fooling > around with this nonsense. The premise of the 'block SRS' policy is that SRS should never be used for "outgoing" mail from a domain. It should only be used to deliver forwarded mail. Therefore, if you receive an SRS MFROM that is a) not a signature (both domains same or one empty) and b) not from a forwarder that you as a receiver have configured then it is spam and should be rejected. Anyone see a problem with these assumptions? Is SRS ever legitimate for anything other than receiver requested forwarding or MFROM signing? -- Stuart D. Gathman <[email protected]> Business Management Systems Inc. Phone: 703 591-0911 Fax: 703 591-6154 "Confutatis maledictis, flammis acribus addictis" - background song for a Microsoft sponsored "Where do you want to go from here?" commercial.