Re: Why SRS really sucks

Tom Lahti <[email protected]> Mon, 27 Mar 2006 10:00:51 -0800
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
>a) There was no proposal to "drop" mail - only to reject it (via 5xx).
>    You are allowed to refuse mail for local policy reasons and
>    provide an explanation via the 5xx message.  E.g.

By "drop" I meant "not deliver".  Rejecting mail based on the local 
part of the MAIL FROM: is a violation of RFC just as much as dropping 
it.  When your boss doesn't get my very important SRS signed email, 
be prepared to explain to him why you are violating RFC, because I 
will be prepared to explain to him that you are and what that means.

>   550 5.7.1 The example.com domain has become an open relay via SRS abuse

Yes, that's fine if the implementation does not automatically detect 
SRS signing in the local part and start rejecting mail based only on 
that criteria.  If SRS is implemented improperly then certainly its 
valid to reject the entire domain (but note: regardless of the local 
part of MAIL FROM: coming from that domain).

>b) When a domain is abusing SRS to the point of clogging your
>    quarantine, my choices (and any other admin dealing with
>    40000+ forged emails to a 6 person office) are to reject *all*
>    mail from the domain, or heuristically try to reject only the mail
>    they are abusing.

The former is your only RFC-compliant alternative.  If you 
heuristically try to reject only the mail they are abusing, its is 
[a] a violation of RFC, and [b] allows the abuser to continue what 
he's doing, shifting the burden of his own administration onto those 
trying to sort out his garbage.  The right thing to do is to force 
him to sort out his own garbage but rejecting the whole domain until 
he fixes it.

>Are you saying that some implementations don't explicitly support
>SRS signing, and we get this instead for the virtual domain?
>
>[email protected]

That's exactly what I'm saying.  In this case the receiving MTA 
should treat this MAIL FROM: the same as it would for any in 
hostdomain.com.  It has NO BUSINESS even noticing that "virtual1.com" 
occurs in the local part, or that the local part begins with 
"SRS".  For all you know, this isn't truly SRS signing but a 
complete, valid account name with no additional semantics.

>However, the "reject SRS" policy that was proposed should probably apply only
>to specific domains that were abusing SRS - at least until the
>distinction between SRS "signing" and "forwarding" is more widely
>understood.

Not at least until we feel like it.  Until either the end of time or 
the RFC's are changed.  Take your pick :P


--
-- =========================
Tom Lahti
Tx3 Online Services

(888)4-TX3-SVC (489-3782)
http://www.tx3.net/
-- =========================