Re: Re: Why SRS really sucks

"Stuart D. Gathman" <[email protected]> Mon, 3 Apr 2006 11:46:48 -0400 (EDT)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Mon, 3 Apr 2006, David Woodhouse wrote:

> On Mon, 2006-04-03 at 11:01 -0400, Stuart D. Gathman wrote:
> > This does not mean SRS is bad.  It is only bad when used as a
> > codependency inspired workaround for broken SPF configurations.
> 
> That's perhaps true, although it's ironic to note that SRS was
> _designed_ as a workaround for the brokenness of SPF.
> 
> You seem to be agreeing with what I said to Stephan -- which is that SRS
> should be used sparingly (if at all), rather than doing it
> unconditionally just in _case_ the recipient has invented some spurious
> reason to reject normally-forwarded mail. Yes?

Yes.  I use it unconditionally for *outgoing* mail (including mail
from internal domains through a gateway MTA) to block fake DSNs.
However, it should be used for actual forwarding *only* when the
recipient:

a) actually requested the forward (unless you want to be an open relay)
b) checks SPF
c) has a broken SPF checker that can't be configured with trusted forwarders

I would not use the existence of a sender SPF policy to decide whether
forwarding SRS is required.  It is strictly a service for SPF recipients
with poor implementations.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.