There is no way for the owner of the overlying domain (who also owns
the subdomain) to force such email to FAIL. There should be a way to
specify "all valid email from this domain and subdomains comes only
from this set of IPs and no others" and SPF fails to provide one.
That's a weakness in the structure of SPF which ought to be fixed.
How do you propose to implement it, other than tree climbing and gross
hacks like the public suffix list?
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg