Re: Why SRS really sucks

"Stuart D. Gathman" <[email protected]> Mon, 27 Mar 2006 08:20:13 -0500 (EST)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Sun, 26 Mar 2006, Tom Lahti wrote:

> I should have also said that any email, whether SRS signed or not, is
> subject to RFC 2821 and 2822.  One of these documents (I can look it up
> later when I'm at my full computer and not a PDA) says that only a mail host
> for the domain in the envelope address can assign any semantics at all to 
> the local part.  Which means: if you detect SRS signatures in the local part
> and drop mail, then you are violating RFC.  You should treat SRS signed mail
> exactly as you would any other mail from the domain in the domain part of
> the envelope.

a) There was no proposal to "drop" mail - only to reject it (via 5xx).
   You are allowed to refuse mail for local policy reasons and
   provide an explanation via the 5xx message.  E.g.

   550 5.7.1 The example.com domain has become an open relay via SRS abuse

b) When a domain is abusing SRS to the point of clogging your
   quarantine, my choices (and any other admin dealing with
   40000+ forged emails to a 6 person office) are to reject *all*
   mail from the domain, or heuristically try to reject only the mail
   they are abusing.

> > Not good enough.  "Signatures" can be for 
> > virtualized domains, where the virtual 
> > domain and the local domain of the mail 
> > host will both appear in the signature.

I'm not sure what you mean here.  Is this a limitation with some
SRS implementations?  For instance, here is a config with virtual
domains and signing:

[srs]
secret = "don't you wish"
fwdomain = hostdomain.com
sign = hostdomain.com, virtual1.com, sub.domain.com
maxage=8
hashlength=8

The virtual domains are signed for outgoing mail just the same as the
forwarding domain, and look like this:

[email protected]
SRS0=/[email protected]

or like this:

[email protected]
SRS0=/[email protected]

Are you saying that some implementations don't explicitly support
SRS signing, and we get this instead for the virtual domain?

[email protected]

Even for those implementations, you just need to have a separate
SRS config for each virtual domain.  

However, the "reject SRS" policy that was proposed should probably apply only
to specific domains that were abusing SRS - at least until the
distinction between SRS "signing" and "forwarding" is more widely
understood.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.