ietf-mxcomp
[Top] [All Lists]

Re: SPF and SenderID

2005-07-21 16:58:39

Arnt Gulbrandsen wrote:

If I were a spammer, I'd get n+1 outgoing MXes where n is the
number of changes you require to forget my past misbehaviour,
then I'd rotate them.

Makes sense.  You'd also manage to change the FQDN used in HELO
when the old FQDN is "burnt".  That's independent of CSV or SPF,
how do reputation systems handle it, start with "assume guilty"
for new FQDNs ?
                  Bye, Frank

P.S. FWIW, John's eplanation matches what I think how it could
work based on CSV or SPF-HELO.  Won't help against backscatter
of course, but that's no bug, only a feature covered by one of
the other schemes like an SPF MAIL FROM FAIL policy / SES / ...