ietf-asrg
[Top] [All Lists]

Re: pros and cons of RMX (Re: [Asrg] Declaration to the world) (fwd)

2003-03-07 12:29:34

As William points out, this raises the point of "which headers should
be authenticated?"

None of the existing header fields contains an identifier which is suitable
as a principal name.  From: is, by design, settable to one or more addresses,
none of which need to match that of the person who sends the mail.  Reply-to
doesn't have to have anything to do with who sends it - it's perfectly
reasonable to ask that replies be sent to a secretary, a list, whatever. 
The SMTP MAIL FROM field is where (non)delivery reports are sent - again,
not the same as the message sender.  Sender is the closest match, but it is so
widely misused as to be useless.

If you want messages to contain some sort of sender identity that works, you
need a new header field for that purpose.  And it's easier to implement
that way anyway.

Keith
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg