Rand,
I personally think that if the PRA lookup returns "none" or
"unknown", MAIL FROM should be checked, and if that test
returns "fail" then the message should be rejected.
RW> You mean if the message has *no* From, Sender, Resent-From, or
RW> Resent-Sender headers, or if there is no SUBMITTER argument?
The new PRA document makes clear that PRA derivation is based on
Re-sent, Sender and From. Indeed, that is exactly what a reasonable
reading of RFC2822 (and RFC822 and RFC733) should cause one to expect.
What would be more than a little strange would be to impart additional
"source responsibility" meaning to a return address (rfc2821.mailfrom),
if re-sent,sender,from were problematic.
d/
--
Dave Crocker <dcrocker-at-brandenburg-dot-com>
Brandenburg InternetWorking <www.brandenburg.com>
Sunnyvale, CA USA <tel:+1.408.246.8253>