ietf-mxcomp
[Top] [All Lists]

RE: DEPLOY: Legal liability for creating bounces from forged messages

2004-08-24 14:44:00

Chris,

You're between a rock and a hard place.  If you simultaneously believe
that all of the following are sinful:

1. To accept and deliver forged mail.
2. To accept forged mail and silently discard it.
3. To accept forged mail and then generate a bounce.
4. To reject forged mail because the sender might generate a bounce.

then you have no alternatives left.

The current drafts give you a way to avoid (1) -- that's their whole
point.  They leave it as a local policy decision as to which of 2, 3 or
4 you choose.  They recommend (4) with a "SHOULD", but you can
reasonably do either of the others.

Today, many large ISPs silently discard mail that they classify as spam.
I expect that those ISPs will choose (2) when implementing SenderID.

Your thoughts about MAIL-FROM, HELO and EHLO don't change the above
calculus at all.  They merely change the details of which messages you
classify as forged.

-- Jim Lyon


<Prev in Thread] Current Thread [Next in Thread>