Re: Why SRS really sucks

"Stuart D. Gathman" <[email protected]> Mon, 27 Mar 2006 09:42:30 -0500 (EST)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Mon, 27 Mar 2006, David Woodhouse wrote:

> On Mon, 2006-03-27 at 04:09 +0200, Johann Steigenberger wrote:
> > And finally: SRS breaks SPF.
> 
> Yes. But SRS is the natural reaction to SPF, on the part of the many
> people out there who just don't care about SPF, or who think it is
> entirely broken in the first place. Something like SRS is _necessary_
> because forwarding _does_ happen in the real world. Those people have
> implemented SRS because they think it's the best option for them, to
> work around the breakage which SPF has caused. That was always expected.

If they really "just didn't care" about SPF, then there would be
no need for SRS.  It is only needed by forwarders because of clueless admins
who reject mail based on SPF - yet make no provision for the forwarders they or
their customers have themselves configured.

And even when SRS is abused, SPF is still fulfilling its promised
function - to keep MFROM domain owners responsible for the mail they send. 
When a domain abuses SRS by forwarding to all and sundry (not just those
who asked for it), it becomes an open relay.  They need to be treated just
like plain open relays were last decade - only we can be a little more
merciful because of the additional control provided by SPF.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.