spf-discuss
[Top] [All Lists]

Re: draft 02.6 ready

2003-11-14 13:21:46
Meng Weng Wong <mengwong(_at_)dumbo(_dot_)pobox(_dot_)com>:
Eric Allman read the 02 draft.  "Good idea, but why so baroque?"

Zing!  He's right, mengwong.  I've wondered the same thing myself.  Props
to you for having the good sense to hear him.

1) The scope modifier is going away.

Fine.
 
   The idea behind scope=header-from,envelope was to block
   service(_at_)paypal(_dot_)com forgeries.  But it turns out to be easier to
   implement this as a mechanism that simply requires the header from to
   match the envelope.  Since nobody has actually asked for this, maybe
   it'll never get used!  We're going to make it optional.

I disagree.  Options are bad.  This capability is not sufficiently
difficult to implement that there is any downside to making it a
mandatory part of the standard.

2) The "default=deny" modifier has turned into the "all" mechanism.
3) The shorthands have changed.
4) The "exec" mechanism has turned into a "redirect" modifier.

That's all good.
 
5) The explanation modifier has become a pointer to a TXT record.

I continue to object to the pseudodomain-plus-hijacking-TXT way of 
representing domain attributes.  It's an ugly kluge.

6) Unrecognized mechanisms now short-circuit to "unknown".
   Unrecognized modifiers are ignored.
7) The "reports" extension mechanism is now the "reports=yes" modifer.

Fine.
 
8) The draft may fission into two, separating the policy gramar from
   the designated sender scheme.

I encourage this thought.  It will help separate the stuff that I
think is good (the policy grammar) from the stuff that gives me mild
heartburn (the particular way you want to embed that notation in DNS
zone files)

I'll do an edit pass over the new draft.
-- 
                <a href="http://www.catb.org/~esr/";>Eric S. Raymond</a>

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.6.txt
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡