ietf-asrg
[Top] [All Lists]

Re: Bounces, was Re: [Asrg] Sender pays vs Forgeries

2003-03-21 03:21:05
Tony Finch <dot(_at_)dotat(_dot_)at> schrieb/wrote:
list-ietf-antispam(_at_)faerber(_dot_)muc(_dot_)de 
(=?ISO-8859-1?Q?Claus_F=E4rber?=) wrote:
One could use special addresses as the envelope recipient which become
invalid after a month.
Mail to these addresses is only accepted if it has a return path of <>
and mail to other addresses only if it has a return path that is not <>.
The addresses would have to contain a timestamp and a digital signature,
which is checked by the MTA that receives mail for the user who uses
such a scheme.

There's already an equivalent solution in RFC 3461.

Detecting bounces by looking for a RFC 3461 messages only works when all
sites implement it. And then you can still have your commercial message  
in the first part of a multipart/report structure (and fake bounce data  
in the following parts).

Special bounce addresses can be deployed on a per-domain (or per-
address) basis without support from hosts that send bounces (_and_ they
can detect forged bounces after MAIL FROM and RCPT TO, i.e. without
DATA).

Claus
-- 
http://www.faerber.muc.de/
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg