ietf-mxcomp
[Top] [All Lists]

RE: Forged Sender (Resent-From) attacks

2004-08-19 11:29:46

 On Thursday, August 19, 2004 1:44 AM, Chris Haynes
[mailto:chris(_at_)harvington(_dot_)org(_dot_)uk] wrote:

<snip>

- More importantly, this allow us to give much clearer 
directions to 
senders in terms of what to publish. You publish the IP 
addresses of 
servers authorized to send mail on behalf of your domain. We're not 
trying to mix this up with the IP addresses of servers that receive 
bounce messages on behalf of your domain.

<snip>


Is it possible that, all along,  there has been a fundamental 
misunderstanding of SPF amongst the designers of Sender-ID?


No there is no fundamental misunderstanding.  There may be a wording
problem, though.  :-)

The point I'm trying to make, and which has been made many times before,
is that there is a semantic difference between the 2821 MAIL FROM
address and the 2822 headers.  So maybe I should have said "the IP
addresses of servers authorized to transmit mail on behalf of the domain
that receives your bounce messages."