ietf-mxcomp
[Top] [All Lists]

Re: When spoofing is.

2004-03-21 08:02:02

Alex van den Bogaerdt <alex(_at_)ergens(_dot_)op(_dot_)het(_dot_)net> wrote:
Why would this be anyone other than the postcard site?

Because they are unwilling to receive their junk back.  I've seen
things as bad as:
...

  Or: EHLO [recipient-ip-address]

  Such nonsense is highly correlated with spam.  The fact that many
MTA's accept such traffic can be viewed as a serious implementation
flaw.

  Well.. not really.  Nothing in RFC 821 leads anyone to believe that
the IP address used in the HELO has to have any value whatsoever.  The
standard was written at a time when there were certain unspoken
expectations, and those were carried into RFC 2821:

  - MTA's are MTA's for one domain
  - everyone uses their IP in the EHLO, so there's no need to specify
    that they need to use it.
  - etc. ...

  Alan DeKok.


<Prev in Thread] Current Thread [Next in Thread>