ietf-mailsig
[Top] [All Lists]

Re: MASS plus Sender-ID

2004-11-22 06:47:31

Indeed there is; see draft-fenton-identified-mail-01.txt section 9.1.4.  The
problem is that there is no way I can think of to differentiate an MTA that
forwards mail to multiple addresses from a spam replay, other than intent and
(possibly) the number of addresses that the messages is forwarded to.  It's
hard to detect even the latter, unless you're a large enough domain to get a
large number of copies of the same message with the same signature.

If verification involves some kind of callback then the sending site
(webmail.com) can track the number of copies of a given message that have
been received. It can then revoke its signature if a threshold is passed,
or rate-limit verifications if the spam decision isn't clear.

Tony.
-- 
f.a.n.finch  <dot(_at_)dotat(_dot_)at>  http://dotat.at/
MALIN HEBRIDES: NORTHEAST 4 OR 5 INCREASING 6. RAIN LATER. GOOD BECOMING
MODERATE.


<Prev in Thread] Current Thread [Next in Thread>