ietf-smtp
[Top] [All Lists]

Re: Sender's Declaration of Identity

2005-05-17 11:27:20
On Tue, 17 May 2005 02:08:44 PDT, David MacQuigg said:

       EHLO  mailserver7.bigforwarder.com
       MAIL FROM:<bob(_at_)sales(_dot_)some-company(_dot_)com>

What do you do next?

*I* get to decide that.  If I wish to do SPF checks, I perform the required SPF
checks.  If I wish to check a Yahoo-style signature, I do that. And so on.
Changing your transaction to read:

       ID spammers-r-us.com
       EHLO mailserver7.bigforwarder.com
       MAIL FROM:<bob(_at_)sales(_dot_)some-company(_dot_)com>

What do *you* do next? (Note that for *ANY* authentication method I've seen so
far, validating the 'spammers-r-us.com' value is the *WRONG* thing to do, 
because
spammers-r-us.com will be set up to verify correctly, even if the EHLO/MAIL FROM
don't).

Now if your proposed tag said:

       ID SPF=YES,YAHOO=NO,CVS=YES

*THAT* I can do something with (namely, short-circuit that auth method with
whatever I do for a 'info-not-found' for that method).

Attachment: pgpRS10LkUVEG.pgp
Description: PGP signature