Re: Why SRS really sucks
"Johann Steigenberger" <[email protected]> Mon, 27 Mar 2006 15:32:42 +0000 (UTC)
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
> *And*, SPF checkers need to use their brain and not reject mail > from forwarders that they as a receiver have set up. Exactley. They have to make exceptions for their own forwarding service ... They can not expect others to break sender policys too, only to compensate their clueless > This is a reasonable policy - except for one very important thing. > While SRS for forwarding is only needed for braindead SPF recipients, > SRS is *very* useful for "signing" MFROM to eliminate "bounce spam" - > spam with an empty mail from that is not a bounce of anything you sent > (even though that was not the original purpose of SRS). There are more easy way to deal with faked bounces. If you have for e.G a good policy, those will not impact on you ... Think about this: What will never be in an authentic bounce? Links to remote hosted pictures, HTML, Non English charsets .... Those could be found in an attached message but not in the bounce itself Should i continue ? Anything which claims to be an NDR and contains such crap will logically not be a bounce, simply reject or discard it :-) You do not need SRS to deal with that :-) >The premise of the 'block SRS' policy is that SRS should never be >used for "outgoing" mail from a domain. It should only be used to >deliver forwarded mail. Therefore, if you receive an SRS MFROM >that is My point of view is that it should NOT be used for anything. It breakes SPF. And this is the Problem. Accept that SPF is a thing usefull for experts and not for lamers. So why supporting lamers with something like SRS? There is no thing that does the job right for all. Domainowners are the only People which have the right to decide, what is allowed on their domains. If Users of those Domains can not live with Domainowners decision, they should probably register their own Domains :-) -- Johann Steigenberger Blacklistmaster at UCEPROTECT-Network http://www.uceprotect.net