ietf-smtp
[Top] [All Lists]

Re: Bounce/System Notification Address Verification

2005-07-04 21:49:21
On Mon, 04 Jul 2005 19:52:12 EDT, Hector Santos said:

Yes Really Bruce. Domain spoofing, forging is a real.

-- read 2505.  If you send to an external site which does
aliasing and sends back to some other local-part at the same domain,
guess what MAIL FROM will be; exactly as you set it.

I still don't think you understood.

I wasn't sure *YOU* understood either, given that you gave Claus grief about
how he was failing to "protect his domain" by not rejecting odd values on
a HELO/EHLO.

Attachment: pgp7sMsW13QBI.pgp
Description: PGP signature