ietf-asrg
[Top] [All Lists]

Re: [Asrg] Position paper, in zipped HTML

2003-03-17 02:33:26

In message <3E756563(_dot_)9090407(_at_)americasm01(_dot_)nt(_dot_)com>, 
"Chris Lewis" <clewis(_at_)nortelnetworks(_dot_)com> wrote:

In a nutshell, if some SMTP client says to you `HELO foo.bar.com' then
6 times out of 10 a forward lookup on `foo.bar.com' will get you the
IP address of that same SMTP client and another 3 times out of 10,
looking up the MX records for `bar.com' will get you the IP address
of that same SMTP client.  So 9 times out of 10 you can accurately
associate a domain name with a given SMTP client, even in the total
absence of rDNS.

That presumes, for example, that every mail server is only authoritive 
for one domain.

It does?  How?

I think that you may perhaps have misunderstood what I actually said,
and/or the limits thereof.

 That breaks even for us.  Breaks hugely for people with 
their own domains mailing thru ISP servers - which we want them to do if 
they're DHCP (for example).

Please note that I never said a word about envelope sender addresses,
or about the domain parts thereof.

I only said that given a random mail server `M' which says `HELO x.y.z'
when it is acting as an SMTP client, the odds are very high (as I myself
have confirmed, empirically) that a forward DNS lookup on x.y.z will
yield the IP address of the SMTP client in question, or that forward
DNS lookups on one or more of the MX names for the domain `y.z' will
yield the IP address of the SMTP client in question.

This is simply a way to validate the name/ownership of a given specific
mail server.  It is entirely independent of, and orthogonal to the
possible transmission of any actual message or messages.

The mail server in question may perhaps be programmed to receive and
accept incoming messages for a number of different domains, and/or it
may be programmed to send outgoing mail for a number of different users
whose return addresses are in different domains, but none of that relates
in any direct way to the mail server's own identity and/or ownership,
which is all I was speaking about in my prior message.
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg