ietf-asrg
[Top] [All Lists]

Re: [Asrg] whitelisting server and not users

2003-04-02 14:55:05
From: Markus Stumpf <maex-lists-spam-ietf-asrg(_at_)Space(_dot_)Net>

...
This approach would also fix a lot of other DNS problems :-)) because
everyone would start to take a lot of care about their RR zones (which
they currently do not, as Bill Mannings statistics show very clearly).

Why whould they start to care about their RR zones?  There are already
far more SMTP servers that require various matching rules among the
HELO value, the reverse DNS name of the STMP client, and the Mail From
client than you could hope to have check for TXT RRs for a year or
two.  However, those many SMTP checking servers are a small minority
because so many outfits have no or ridiculous reverse reverse DNS,
that no one who cares about false positives can use it.

As far as I can see, the only way to get such a rule in place is to
convince a very large SMTP client to impose it.  For example, AOL's
sudden requirement that the envelope Mail_From domain name resolve
made it possible for that rule to be the default.

This sort of transition problem differs from the problem of convincing
80% of the Internet to do something new like use certs or switch to
something other than SMTP.  When AOL started requiring valid sender domain
names, more than 80% of legitimate mail already met the rule.  AOL just
pushed most (but not all) of the small minority to get their acts together.


Vernon Schryver    vjs(_at_)rhyolite(_dot_)com
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg