ietf-822
[Top] [All Lists]

Re: authenticating the source of mail

2002-05-19 09:25:08


Arnt Gulbrandsen wrote:

One day my IP connectivity to the main office is broken, but I can
talk to most of the world. No problemo, I just comment out the
"smarthost" stuff in my server's sendmail.cf and see that my
outgoing mail works again.

Next day the main office is back on the net, but but I forget to
reenable the smarthost setting, and noone discovers it until the main
office, confident that everyone's using the central smarthost, adds an
MS RR and some of my mail starts bouncing.

Would the domain-wide PTR mapping work for this branch office setup? Your
mail appears to be coming from a fixed network associated with your
$cityname branch office, so you could theoretically just point to that
subdomain and be done with it.

There are certainly going to be exception cases, which cannot be designed
for. The best choice for those networks is not to use MS RRs at all. If
the mail network doesn't use a set of authorized relay servers, then there
is no reason to list anything in MS. But in your example, it seems that
the domain-wide PTR would work. Would it? If not, would something else
work as well?

-- 
Eric A. Hall                                        http://www.ehsco.com/
Internet Core Protocols          http://www.oreilly.com/catalog/coreprot/

<Prev in Thread] Current Thread [Next in Thread>