Re: SRS for postfix ?

"John A. Martin" <[email protected]> Thu, 17 Aug 2006 16:12:41 -0400
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
--=-=-=

>>>>> "Stuart" == Stuart D Gathman
>>>>> "RE: Re: SRS for postfix ?"
>>>>>  Thu, 17 Aug 2006 15:21:17 -0400 (EDT)

    Stuart> It is not at all necessary to use SRS with SPF.  SRS is a
    Stuart> workaround for forwarders whose customers are unwilling or
    Stuart> unable (their mail provider doesn't let them) to properly
    Stuart> configure their SPF checker.  A much less intrusive way to
    Stuart> handle receiver initiated forwarding is a
    Stuart> trusted-forwarder list - either public or private.  Of
    Stuart> course, a forwarder that doesn't check SPF just becomes a
    Stuart> spam conduit.  But this happens with or without SRS.

    Stuart> I do not SRS for forwarding.  I use it for MFROM signing
    Stuart> to reject forged DSNs from MTAs that do not check SPF.

    Stuart> I repeat - SRS is *not* needed for an effective SPF
    Stuart> implementation.

    Stuart> SRS for forwarding is only needed by forwarders with
    Stuart> clueless/powerless clients.

Agreed.  Violently. :) However it has not been clear to me how to do
SRS MFROM signing to reject forged DSNs with Postfix.

        jam