Re: private relay ... could i use srs to avoid spffail?

"Stuart D. Gathman" <[email protected]> Fri, 1 Dec 2006 09:56:44 -0500 (EST)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Fri, 1 Dec 2006, wayne wrote:

> Doesn't doing SRS on all outgoing email cause problems with certain
> mailing lists (ezlm?), vacation programs and other (broken) stuff that
> assumes the 2821.MAILFROM stays constant?

Yes it does.  Another problem is broken MTAs that think '+' is an
illegal localpart char.  I have a small list of broken MTAs and disable
SRS when sending to those domains.  I reject DSNs from the
broken MTAs (if they do CBV *and* have broken MTA, I just don't deal
with them).  Ironically, one of the broken MTAs is/was the MTA
for the SES mailing list (which suffers from the same problem).
This approach might not scale, however.

> Some people have also suggested that by using SRS on all outgoing
> email lets you reject bogus bounces, but in order to do that you have
> to make sure that *ALL* legitimate email sent using your domain name
> gets processed by SRS.  Roaming users and people working form home and
> such have to be tought to always use RFC2476's SMTP submission port
> (587).

Making roaming users always relay through home is essential for a decent
SPF policy also.  Note that Outlook must use smtps (465) instead.
Another solution is an SSH tunnel (e.g. Putty for Windows) or a VPN.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.