ietf-822
[Top] [All Lists]

Re: MTS transparency and anonymity

2005-02-28 10:43:53

On Mon, 28 Feb 2005, Keith Moore wrote:

the best way I know to deal with that problem is to recognize bounces
(not just by return-path but by message format) and to correlate them with
a Sent IMAP mailbox.

This is just another variant of including a cookie in outgoing email which
you check for in the bounces that come back.

Putting the cookie in the message data doesn't work in general because
many bounces are unparseable, or they don't include enough of the original
message. The extreme example of this is vacation messages which usually
include nothing of the original; also some bounces have extremely
abbreviated copies of the original header.

more ideally, return-paths would be authenticated (in the sense that the
sender needs to be able to demonstrate he has the right to use that
return-path), and MTAs wouldn't bounce messages that failed authentication.

This is the fallacy of universal deployment: you can't assume that
everyone will upgrade their systems to conform to best current practice,
so you can't rely on BCP to eliminate backscatter.

Tony.
-- 
f.a.n.finch  <dot(_at_)dotat(_dot_)at>  http://dotat.at/
ROCKALL MALIN HEBRIDES: WEST VEERING NORTH 6 TO GALE 8, PERHAPS SEVERE GALE 9
LATER. RAIN THEN WINTRY SHOWERS. MODERATE OR GOOD.