I appreciate the following principle:
On the other hand, it is not necessary to reach a consensus
regarding the actions that various parties take once a message has
been determined to be spoofed. This can be done unilaterally -- one
agent might decide to discard a spoofed message while another decides
to add a disclaimer.
It separates cleanly the technical engine from the policy. But the I-D
contradicts itself when:
3. Decision Model
An SMTP server receiving this result SHOULD accept the message.
(Many other similar sentences in this section.)
IMHO, such sentences should be deleted completely or replaced by
something harmless like "A SMTP server can then act on the basis of
this result".