Re: Why SRS really sucks

Stephan Menzel <[email protected]> Mon, 27 Mar 2006 21:48:01 +0200
Newsgroups gmane.mail.spam.srs.general
Organization VvJ
Message-ID <[email protected]>
Am Montag, 27. März 2006 20:51 schrieb Tom Lahti:
> >Well, basically I can agree to this. However, we are doing in some
> >circumstances pretty much the same Johann showed in his example.
>
> Which means: not an example of what we're discussing.  Johann's
> example is perfectly compliant.

Yes.
I know, the example was not supposed to emphasize the original point of this 
discussion but rather to show a general acceptance to violate certain RFC 
demands simply to be able to survive in a scenario of heavy spamming. I just 
wanted to add my two cents there.

> We're discussing an MTA examining the local part of MAIL FROM: where
> the domain is not the MTA's domain, and trying to parse out meaning
> from it (beyond a simple one-to-one comparison).  Are you doing THAT?

Well, if I understand you right here, yes we do.
But consider a scenario with many user dependend configurations. Let's say, 
you offer SPF checks for your users. And some users have it activated with a 
setting like 'deliver to spam folder', some users say 'no, I want this 
blocked' and there will also be users who say 'I don't want any SPF 
checkings'. Same thing goes not only for SPF but for many other spam 
protection modules you might invoke there like internal or external 
blacklists etc.
In this case, you have almost no chance to give the error right after MAIL 
FROM. You must be able to know, which user this mail will be adressed to to 
determine which settings apply. Regarding the RFC, afaik this won't let you 
any option other than receiving the DATA.
Or did I get you wrong here?

Greetings...

Stephan