ietf-mailsig
[Top] [All Lists]

Re: MASS plus Sender-ID

2004-11-21 21:48:46

Justin Mason wrote:

hmm, you might be on to something there, that does indeed seem to be a
replay attack that can be used to deliver spam.

Indeed there is; see draft-fenton-identified-mail-01.txt section 9.1.4. The problem is that there is no way I can think of to differentiate an MTA that forwards mail to multiple addresses from a spam replay, other than intent and (possibly) the number of addresses that the messages is forwarded to. It's hard to detect even the latter, unless you're a large enough domain to get a large number of copies of the same message with the same signature.

-Jim


<Prev in Thread] Current Thread [Next in Thread>