spf-discuss
[Top] [All Lists]

Re: DNS RRtypes: changing PI

2003-10-20 11:27:08
On Monday 20 October 2003 08:45, Izzy Kindred wrote:

I have no problem with _smtp_client DNS name.  While it is an issue
that many people have raised, I do not remember anyone mentioning that
there is a precedent for using underscores in DNS names.  It has been
done before.

Indeed - There is absolutely no reason at all why an underscore cannot be used 
in a domain name (or any other charecter, AFAIK). However, we are using this 
in an SMTP context - that is why the issue has been raised before. I can't 
comment about other mailers, but Exim will choke on any query with an 
underscore unless it is told to 'relax' the rulebook. Allowing the underscore 
would break a separate validity check.

The converse question is: Is there any reason why a dash could not be 
substituted for the underscore? What is the (realistic) risk of a collision? 
Is there any reason why SPF cannot use this method instead?

RFC 2782, the RFC for SRV RRs, specifies that underscores should be
used at the beginning of domain names to avoid collisions between SRV
RRs and other RRs "that occur in nature".

From the introduction to RFC 2782:
Introductory example

  If a SRV-cognizant LDAP client wants to discover a LDAP server that
  supports TCP protocol and provides LDAP service for the domain
  example.com., it does a lookup of

     _ldap._tcp.example.com

Since SPF will not be delivering mail to the _smtp_client RRs, and
since the _smtp_client will never be part of the domain of an email
address, I claim _smpt_client does NOT conflict with RFC2821 2.3.5.
In other words, _smtp_client domain names fall outside the universe of
RFC2821, and therefore there is no conflict.

Except that SPF oesn't deliver mail at all - it is simply a query mechanism 
for the MTA to interrogate if it wishes to do so. Though the _smtp_client 
domain name will never be part of the the email address, nevertheless, the 
query will be used within the SMTP process.

Note that the objection relates only to using the _smtp_client with the TXT 
RR. If SPF follows the SRV RR route, and it uses LDAP, then other 'standards' 
apply.

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.txt
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡


<Prev in Thread] Current Thread [Next in Thread>