Re: Why SRS really sucks
Tom Lahti <[email protected]> Mon, 27 Mar 2006 10:00:51 -0800
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
>a) There was no proposal to "drop" mail - only to reject it (via 5xx). > You are allowed to refuse mail for local policy reasons and > provide an explanation via the 5xx message. E.g. By "drop" I meant "not deliver". Rejecting mail based on the local part of the MAIL FROM: is a violation of RFC just as much as dropping it. When your boss doesn't get my very important SRS signed email, be prepared to explain to him why you are violating RFC, because I will be prepared to explain to him that you are and what that means. > 550 5.7.1 The example.com domain has become an open relay via SRS abuse Yes, that's fine if the implementation does not automatically detect SRS signing in the local part and start rejecting mail based only on that criteria. If SRS is implemented improperly then certainly its valid to reject the entire domain (but note: regardless of the local part of MAIL FROM: coming from that domain). >b) When a domain is abusing SRS to the point of clogging your > quarantine, my choices (and any other admin dealing with > 40000+ forged emails to a 6 person office) are to reject *all* > mail from the domain, or heuristically try to reject only the mail > they are abusing. The former is your only RFC-compliant alternative. If you heuristically try to reject only the mail they are abusing, its is [a] a violation of RFC, and [b] allows the abuser to continue what he's doing, shifting the burden of his own administration onto those trying to sort out his garbage. The right thing to do is to force him to sort out his own garbage but rejecting the whole domain until he fixes it. >Are you saying that some implementations don't explicitly support >SRS signing, and we get this instead for the virtual domain? > >[email protected] That's exactly what I'm saying. In this case the receiving MTA should treat this MAIL FROM: the same as it would for any in hostdomain.com. It has NO BUSINESS even noticing that "virtual1.com" occurs in the local part, or that the local part begins with "SRS". For all you know, this isn't truly SRS signing but a complete, valid account name with no additional semantics. >However, the "reject SRS" policy that was proposed should probably apply only >to specific domains that were abusing SRS - at least until the >distinction between SRS "signing" and "forwarding" is more widely >understood. Not at least until we feel like it. Until either the end of time or the RFC's are changed. Take your pick :P -- -- ========================= Tom Lahti Tx3 Online Services (888)4-TX3-SVC (489-3782) http://www.tx3.net/ -- =========================