ietf-asrg
[Top] [All Lists]

Re: [Asrg] MXs Used As Authentication - Why RMX?

2003-09-19 18:37:17
Sabahattin,

SG>   Why can't you just
SG> resolve the given envelope sender domain, check all of the MXs hostnames
SG> and see if any of them matches your connecting machine's IP after 
SG> resolution to addresses?  The hostname could come either from the SMTP

 Other have noted the fact that inbound SMTP often goes through
 different hosts than outbound SMTP.

 Another flaw with proposals like RMX is that the sender's domain name
 in the Mail-From field often does not have any relationship to the
 domain name of the machine (MTA) that is actually sending the email.
 The Mail-From specifies a return address. It is like the return address
 on a paper mail envelope. When you send paper mail, does the envelope
 return address does not contain any information about the postal box
 you put the envelope into.

 The RMX proposal would require that you pre-register the sender's
 domain name with any and all "postal boxes" that you might send
 through. This is especially a problem for anyone who is mobile and
 sends mail through different relays. More generally, the administrative
 overhead of such a scheme is problematic.

d/
--
 Dave Crocker <mailto:dcrocker(_at_)brandenburg(_dot_)com>
 Brandenburg InternetWorking <http://www.brandenburg.com>
 Sunnyvale, CA  USA <tel:+1.408.246.8253>, <fax:+1.866.358.5301>


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>