ietf-asrg
[Top] [All Lists]

Re: [Asrg] Is there anything good enough? - Spoofing stats

2003-05-08 10:58:49
Vernon Schryver <vjs(_at_)calcite(_dot_)rhyolite(_dot_)com> wrote:
No, you are falling for the intentional misrepresentation or lie that
is labelling mail that comes from one domain with another domain as
sender as "forgery."

  So far as the recipient can tell, it's no different than forged-spam
messages.

  Q: Why is it up to the recipient to verify the identity of the
     sender?

  I understand that methods like PGP, and client-side certificates
can allow the recipient to verify the identity of the sender, despite
their alleged "from" address, or network location.  To me, proposals
like RMX allow similar verifications, but at a lower cost.

  Alan DeKok.
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg