Re: Over 255 character SPF record with TinyDNS/djbdns
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
You might want to remember the SPF ddos attacks, and consider the 14 serious problems that the IETF considered when the MX-COMP Working Group rejected SPF as a protocol. SPF is an experimental protocol. Spammers were the first to adopt SPF---Source: report to IETF MX-COMP on SPF utilization. SPF is used by spammers to say "I'm not a spammer", which is of course, false. The working group rejected, SPF but the current RFC was put through as an individual submission by Bill Schlitt, who associates with open relay abusers. I'll hit the highlights of why SPF is bad: o SPF just identifies the outbound relays to bots when the ISP blocks port 25 to residential customers. o It is better to add negative points to email if it comes from a domain with SPF records. o You never want to verify SPF records because of the attacks using the script language. (DOS, buffer overflow). o SPF records can be spoofed, and make it appear to morons that the fabricated email was "authenticated by SPF". This problem is especially an concern when dealing with seemingly "radical anti-spammers" who were really spammers engaged in extortion efforts; the "spam and extort" scam. o SPF records can be spoofed and cause email to be blocked from legitimate servers. While there are a fair number of sites that publish SPF records, there are no serious sites that verify/reject mail based on SPF. So its a total waste of time. SPF does not, and cannot help stop spam. Spammers just setup SPF records. Protocol design cannot (by information theoretic reasons) ever help stop spam. Those who tell you differently are selling perpetual motion machines. Whenenver you come upon a blacklist that is the only blacklist that can stop some spam (e.g. ORBS, OSIRUSOFT, SORBS), you are being scammed by that blacklist; they are sending the spam. I found ORBS and OSIRUSOFT abusing open relays to promote their services in the late 90s. The SPF proponents (like Schlitt) are associates of those same people, and Schlitt has lied on wikipedia entry to cover up their bad activities. So the SPF author is discredited. The forged email scam works this way: they forge email, and then sell something to quit. SPF can't make forged email stop. Its just the "consulting service" they sell as a cover for what amounts to a scam or extortion. I've recently learned that DNS blacklists appear to be analyzing user's traffic for "market intelligence" they can sell or use. When you use a DNS blacklist, they get an idea of who you are communicating with. The IP is in the DNS query, as is your source IP. The rate of queries and TTL indicates something about the volume. They can change the TTL if they need more detail. So avoid DNS blacklists. Avoid DNS-based anti-spam tools. --Dean On Tue, 9 Feb 2010, Matthew Dempsky wrote: > On Tue, Feb 9, 2010 at 1:41 PM, <[email protected]> wrote: > > I am looking for help with the correct syntax for specifying a longer than 255 characters SPF record in TinyDNS. Here is what I have right now but it splits the result of the lookup after 127 characters: > > You can safely ignore the TXT record string splitting. SPF clients > are required to rejoin them together before interpreting the contents. > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494