spf-discuss
[Top] [All Lists]

RE: SPF reporting mechanism

2003-10-26 08:37:21
On Sun, 2003-10-26 at 06:13, Marc wrote:
A couple of responses in one:

First, Sam originally wrote
Also, it might be a good idea to force reporting addresses to be
in the same domain where they are listed to ensure that reports
aren't sent somewhere bogus.

I don't think that this would be helpful.  In the situation where an
organization has their email provider outsourced, the email hosting provider
would probably want to be the one to receive the messages and would likely
want to have a single inbox for all such reports.  For them to have a
mailbox in each of their client's domains would not be likely or efficient.

I agree - but you might want to limit the address to that of the DNS
host domain (since they have control over the DNS to some extent) as
well as the actual recipient domain.

I expect the reverse on the DNS address would be what to check.

Also, in the matter of sending a notice every time there is a deny - it
may be reasonable to set a mechanism somewhat like "vacation" uses
(used) where the notice is sent only once every so often if the address
is the same - in this case the failure message originator domain? - is
the same.

The other alternative is something like syslogd where it shows only a
count if the activities are identical and come close to one another.
This would imply a message buffer and some programmable timeout for
sending whatever was in the buffer either as a summary or as individual
lines. The buffer might be x lines long or for x minute/hours or a
combination of both. Something like send every 30 minutes or whenever
there are 100 lines in the buffer, whichever comes first unless there
are no lines.

This would give at most 48 reports a day unless there was massive
activity.

richard

-- 
-
Richard C. Pitt                 Pacific Data Capture
richard(_at_)pacdat(_dot_)net           604-644-9265
http://richard.pacdat.net       www.pacdat.net
PGP Fingerprint: FCEF 167D 151B 64C4 3333  57F0 4F18 AF98 9F59 DD73

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.txt
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡