spf-discuss
[Top] [All Lists]

Re: [spf-discuss] How does SPF prevent forgery?

2006-02-16 15:36:17
SPF checks 2821 addresses.  It makes no assertion about 2822 addresses.

Some would call 2822 address fakes "phishing", not forgery.

For 2822 checking, you should look at PRA (aka sender id). But there are serious caveats with using it, so be careful.

Terry

Wally Winchester wrote:
Hello.

If SPF only checks the envelope from address, how does it prevent
forgery?

i.e. how does it prevent a user getting an email From: 
person(_at_)bank(_dot_)com?

WW

--
Terry Fielder
terry(_at_)greatgulfhomes(_dot_)com
Associate Director Software Development and Deployment
Great Gulf Homes / Ashton Woods Homes
Fax: (416) 441-9085

-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your subscription, please go to http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com