ietf-asrg
[Top] [All Lists]

Re: [Asrg] misconception in SPF

2012-12-10 14:09:12
On 12-12-10 12:00 PM, Christian Grunfeld wrote:

you get no answer because there is not SPF record for www.google.com,
so you can forge emails as if they come from www.google.com even if
there exists an SPF record for google.com !

The point was about your #2.  Those using ?all.  Eg: you.

People don't use !all, for the same reason gmail (you) uses ?all.

With that huge problem in the way, trying to solve <hostname>.<spf'd
name> doesn't seem very useful.

The "solution" of publishing SPF records for all A'd hosts works
sometimes, but sometimes it just doesn't scale.

Just imagine how many hostnames that Google and Gmail have between them.


_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg