Re: Why SRS really sucks

Julian Mehnle <[email protected]> Mon, 3 Apr 2006 12:02:38 +0000
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Johann Steigenberger wrote:
> Example:
> If the recipient System is an UCEPROTECT-Server, and your System or
> settings do not match the requirements to be accepted, you get a NDR
> which tells you why your mail was rejected, and how you can whitelist
> your emailadress. 
>
> If you go to the Whitelist - Page and enter [email protected] it will
> cause your mail will get throu if your envelope-from reflects that.
> But if your Envelope-From is [email protected], and your User does not
> know that, whitelisting [email protected] will not work for you ....

Challenge/response systems are broken by design (and if UCEPROTECT does 
that kind of thing, it is, too).  And even then, they will usually not 
require manual entry of envelope sender addresses.

> SRS makes that also impossible for senders .... thats the consequence of
> faking envelope datas ...

SRS does not fake envelope sender addresses.  If you believe that, then you 
have understood _neither_ the point of SRS _nor_ that of SPF.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFEMQ7ewL7PKlBZWjsRAlXMAKChNHIrrKN818vmnuOkgy8++4y1NQCgsKs3
NOHfelet6kaAxoNirjZ08Vc=
=51Em
-----END PGP SIGNATURE-----