ietf-mxcomp
[Top] [All Lists]

RE: DEPLOY: Misuse of Resent-From

2004-08-26 13:58:02

In a long message, Doug Otis says (I think) that SenderID is broken
because
(1) We verify the PRA, which isn't just the 2822 From, and
(2) We don't verify the identity of the MTA that sent the message.

While agreeing with (1) and (2), the conclusion that that SenderID is
broken doesn't follow.

He argues that merely validating the EHLO domain is far better.  I
disagree.

-- Jim Lyon


<Prev in Thread] Current Thread [Next in Thread>