Re: private relay ... could i use srs to avoid spf fail?

"Stuart D. Gathman" <[email protected]> Fri, 1 Dec 2006 09:04:54 -0500 (EST)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Fri, 1 Dec 2006, David Woodhouse wrote:

> > i think (please correct me if i'm wrong!) this would cause spf failure 
> > .... if [email protected] is using SPF on domain.com, this would cause 
> > spf failure if delivered via my relay
> 
> Yes, but that would be the fault of the recipient -- they should stop
> using SPF if it's rejecting valid mail.

This is correct in the case of forwarding initiated by the receiver.
Receivers should never check SPF for non-SRS forwarders.

However, it doesn't sound like this is not a case of receiver forwarding,
because he said "from a certain network".  It sounds like he is
providing an SMTP relay service for senders.  In which case, the
*senders* need to mention the relay in their SPF records (if any).
If they can't do that for some reason, then you can't use the original
sender domain in MAIL FROM, and must rewrite MAIL FROM is some fashion
(e.g. SRS).

> I recommend that you don't use SRS on forwarded mail. If you find you
> have problems with people rejecting mail for SPF failure, contact them
> and explain that they should not be using SPF. It usually seems to work
> on the people who've been taken in by the SPF 'marketing' and who didn't
> realise that SPF was incompatible with mail in the real world today.

This is basically correct, except David seems to be anti-SPF, and you should
actually contact them and explain that they should not be using SPF *for their
own forwarders* - duh.  Since David is a forwarder, that takes care of his
problem without throwing the baby out with the bathwater.

Many large domains do not provide a way to configure or track their
end-users forwarders.  Those domains should indeed stop rejecting on SPF
at all.  But it is still helpful to publish SPF so that the rest of us
can reject all the forgeries - since these domains (yahoo.com,
hotmail.com, etc) tend to be the most forged.  (Yahoo doesn't publish
SPF, but I configure a subsitute policy of "v=spf1 ptr -all" since all
their outgoing server names end in "yahoo.com".)

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.