RE: private relay ... could i use srs to avoid spffail?

Mark <[email protected]> Fri, 01 Dec 2006 12:20:51 GMT
Newsgroups gmane.mail.spam.srs.general
Organization Asarian-host
Message-ID <[email protected]>
> -----Original Message-----
> From: David Woodhouse [mailto:[email protected]]
> Sent: vrijdag 1 december 2006 11:13
> To: [email protected]
> Subject: Re: [srs-discuss] private relay ... could i use srs
> to avoid spffail?
>
>
> > i wondered if i could use srs to get round this in some way
> > .... treat each email as if it were being forwarded from
> > the server's default email address insted. Does this sound
> > feasable? if so, am i right in thinking  that the final
> > recipient would see the 'tagged' srs address as the 'from'
> > in their email client?
>
> It wouldn't appear in the From: address; only in the Return-Path:. But
> the return-path is the most reliable way of filtering traffic from
> mailing lists into the appropriate folder, so some people _do_ use it
> and care about it. I would be reluctant to mangle it without good
> reason.

SPF is an SMTP layer protocol (extension). Unlike RFC 2822 layer protocols
like DomainKeys and SenderID, SMTP envelope information, while the MTA may
make parts of it visible in headers, belongs to a different layer. An MUA
relying on SMTP session info to filter traffic from mailing lists into the
appropriate folder, runs the risk of finding a discrepancy between what
occurs in the SMTP dialogue and what addresses are actually listed in the
mail headers (from the DATA phase). Without having grounds to complain,
that is: if you've always relied on using SMTP envelope data in an MUA,
then SPF "breaking" your little setup really only accentuates your
ill-reliance on it.

> I recommend that you don't use SRS on forwarded mail. If you find you
> have problems with people rejecting mail for SPF failure, contact them
> and explain that they should not be using SPF. It usually seems to work
> on the people who've been taken in by the SPF 'marketing' and who didn't
> realise that SPF was incompatible with mail in the real world today.

I recommend you use SRS on forwarding mail. It's an excellent way for MTAs
to take responsibility for the relay. And "breaks" nothing, save the
ill-conceived schemes of those who can't tell their layers apart.

> It usually seems to work
> on the people who've been taken in by the SPF 'marketing' and who didn't
> realise that SPF was incompatible with mail in the real world today.

With those scare-tactics we'd all still have open relays.

SMTP "in the real world today" is simply broken. It was designed with the
now naive looking thought that people would never take advantage of it and
abuse it. If SPF "breaks" anything, then it's that precise breakage.

- Mark 
 
        System Administrator Asarian-host.org
 
---
"If you were supposed to understand it,
we wouldn't call it code." - FedEx