Re: private relay ... could i use srs to avoid spffail?

Julian Mehnle <[email protected]> Fri, 1 Dec 2006 23:32:02 +0000
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Michael Weiner wrote:
> On 12/1/06 10:08 AM, "wayne" <[email protected]> wrote:
> > This is actually one place that SPF can help, even if you prefer other
> > systems.  By putting a "tracking exists" in an SPF record and
> > monitoring your name server logs, you can often tell who is not
> > relaying email through your authorized MTAs.  Just use something like:
> >
> > domain.tld TXT  "v=spf1
> > exists:_h.%{h}._l.%{l}._o.%{o}._i.%{i}._spf.%{d} ?all"
>
> I do not follow this 'tracking exists' record...could you explain in a
> little more detail please?!?

The point of such a "tracking exists" mechanism is to receive DNS 'A' 
queries for artificial domain names containing information about the SMTP 
sender of e-mail messages using your domain.  You can then use the 
received DNS queries to compile statistics on who sends mail using your 
domain.

Of course you need to send empty DNS responses to all queries or the
"exists:" mechanism would match and thus authorize the sending.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFFcLtywL7PKlBZWjsRAssUAKCsaSwHul7UbyqJT9ZjBfgaRARxfQCg+DmW
VH9lLli5O0N1u5trvMCNbsY=
=ha1p
-----END PGP SIGNATURE-----