Re: Over 255 character SPF record with TinyDNS/djbdns

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
You might want to remember the SPF ddos attacks, and consider the 14
serious problems that the IETF considered when the MX-COMP Working Group
rejected SPF as a protocol.

SPF is an experimental protocol.  Spammers were the first to adopt
SPF---Source: report to IETF MX-COMP on SPF utilization.  SPF is used by
spammers to say "I'm not a spammer", which is of course, false.

The working group rejected, SPF but the current RFC was put through as
an individual submission by Bill Schlitt, who associates with open relay
abusers.

I'll hit the highlights of why SPF is bad:

 o SPF just identifies the outbound relays to bots when the ISP blocks
port 25 to residential customers.

 o It is better to add negative points to email if it comes from a
domain with SPF records.

 o You never want to verify SPF records because of the attacks using the
script language. (DOS, buffer overflow).

 o SPF records can be spoofed, and make it appear to morons that the
fabricated email was "authenticated by SPF".  This problem is especially
an concern when dealing with seemingly "radical anti-spammers" who were
really spammers engaged in extortion efforts;  the "spam and extort"  
scam.

 o SPF records can be spoofed and cause email to be blocked from
legitimate servers.


While there are a fair number of sites that publish SPF records, there
are no serious sites that verify/reject mail based on SPF. So its a
total waste of time.  SPF does not, and cannot help stop spam.  
Spammers just setup SPF records.  Protocol design cannot (by information
theoretic reasons) ever help stop spam. Those who tell you differently
are selling perpetual motion machines.

Whenenver you come upon a blacklist that is the only blacklist that can
stop some spam (e.g. ORBS, OSIRUSOFT, SORBS), you are being scammed by
that blacklist; they are sending the spam.  I found ORBS and OSIRUSOFT
abusing open relays to promote their services in the late 90s.  The SPF
proponents (like Schlitt) are associates of those same people, and
Schlitt has lied on wikipedia entry to cover up their bad activities.  
So the SPF author is discredited. The forged email scam works this way:  
they forge email, and then sell something to quit.  SPF can't make
forged email stop. Its just the "consulting service" they sell as a
cover for what amounts to a scam or extortion.

I've recently learned that DNS blacklists appear to be analyzing user's
traffic for "market intelligence" they can sell or use.  When you use a
DNS blacklist, they get an idea of who you are communicating with. The
IP is in the DNS query, as is your source IP. The rate of queries and
TTL indicates something about the volume.  They can change the TTL if
they need more detail.

So avoid DNS blacklists. Avoid DNS-based anti-spam tools.

		--Dean

On Tue, 9 Feb 2010, Matthew Dempsky wrote:

> On Tue, Feb 9, 2010 at 1:41 PM, <[email protected]> wrote:
> > I am looking for help with the correct syntax for specifying a longer than 255 characters SPF record in TinyDNS. Here is what I have right now but it splits the result of the lookup after 127 characters:
> 
> You can safely ignore the TXT record string splitting.  SPF clients
> are required to rejoin them together before interpreting the contents.
> 
> 

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 256 5494
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.