ietf-asrg
[Top] [All Lists]

Re: [Asrg] DNS-based Email Sender Authentication Mechanisms: aCritical Review

2009-05-26 18:20:21
Jose-Marcio Martins da Cruz wrote:

Well. Me too, I don't understand why it could be interesting to check SPF in the MUA. It may be interesting to check SPF when one have access to both sender domain and IP address of the SMTP client connecting to the MTA. This information isn't usually available to the MUA, unless it will trust on data available on headers.

The Thunderbird SPF/DK plugin, for example, has a configuration option that tells it how to parse the Received lines to pluck out the IP and HELO recorded in the Received line the user's perimeter MTA has generated.

It works well enough in that regard.

[The plugin isn't compliant with SPF per-se, it checks From:, because it usually can't get the MAIL FROM. This is configurable.]

I experimented with it. It works. But doesn't add enough to be worth while if you already have decent MTA-end filtering.

If you don't have decent MTA filtering, it might be worthwhile.
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg

<Prev in Thread] Current Thread [Next in Thread>