ietf-mxcomp
[Top] [All Lists]

Re: co-chair judgment of consensus related to last call period of 23-Aug-2004 to 10-Sept-2004

2004-09-12 13:35:31

George Mitchell wrote:

I think everyone agrees on "mailfrom", but not on "pra".

Not sure about everyone, but certainly me.

 Also, what happened to "helo"?

IIRC the idea was to discuss CSV after SPF, and adding it now
before this discussion could be confusing.  As soon as we have
completed spf2.0/mailfrom adding other scopes like PRA or HELO
is easy.  Maybe PRA is then unnecessary, and we find a simple
solution by matching the relevant headers against MAIL FROM:

If nothing matches, and if there's no Sender then it's probably
a case of "2476bis 8.1 MAY-be not", otherwise it's a phisher.

This could also solve the problem mentioned by Wayne and Anne:
| In this sense, neither protecting almost invisible things
| like the Return-Path: nor the Resent-From: header really
| satisify their concerns.
                            Bye, Frank



<Prev in Thread] Current Thread [Next in Thread>