spf-discuss
[Top] [All Lists]

Re: bugs in rfc2821

2004-01-23 06:50:29


On 22 Jan 2004 at 13:15, Meng Weng Wong wrote:

On Thu, Jan 22, 2004 at 01:13:45PM -0500, John A. Martin wrote:
| 
| Are you perhaps referring to rfc2821 Section 4.1.4 Paragraph 6:
| 
|         An SMTP server MAY verify that the domain name parameter in
|         the EHLO command actually corresponds to the IP address of the
|         client.  However, the server MUST NOT refuse to accept a
|         message for this reason if the verification fails: the
|         information about verification failure is for logging and
|         tracing only.
| 
| This is IMHO usually read to mean that a server may refuse to accept a
| message for whatever reason except for the reason that the parameter
| in the EHLO command does not correspond to the address of the client.
| I'm sure there are those that argue otherwise but not among the more
| active anti-SPAM practitioners many of whom reject mail for various
| reasons involving the EHLO parameter.
| 

I consider this a bug in 2821.  I don't know the reasoning that went
into it but I think that text needs to change.

I agree! My mail server will reject the EHLO for a number of reasons. I 
for one don't give a damn about that statement since it's a way that 
the spammers can get through. Most of my rejections are due to the 
sender using one of my domain names or my IP address. My server does 
not yet allow checking if the domain name resolves.


The other thing I would fix is the "implicit MX" rule where a host only
has an A record.

I've used a CNAME for a long time and never seen a problem. I don't 
think I have ever seen a mail reject because of it.

The other thing, as I have stated here before, that needs to be fixed 
is requiring that the "MAIL FROM" be a valid supported address on the 
sending system and not what the user supplies. That will turn into the 
return-path once the message gets to the user. The "MAIL FROM" should 
always be who sent the message and if forwarded the forwarder is the 
sender.



-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.4.txt
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡


----------------------------------------------------------------------
John Warren, President            | Tel.: +1 714-573-9650
Warren Engineering                | Fax:  +1 714-573-9289
14681 Danborough Rd.              | 
mailto:jwarren(_at_)wenet(_dot_)tustin(_dot_)ca(_dot_)us
Tustin, CA 92780-6755             | 
mailto:info(_at_)wenet(_dot_)tustin(_dot_)ca(_dot_)us
                                  | http:Someday.com
+--------------------------------------------------------------------+
| Any and all use of my email address for bulk email without my      |
| expressed permission is prohibited. This means NO JUNK EMAIL, SPAM.|
| Support the anti-Spam amendment, Join at http://www.cauce.org/     |
+--------------------------------------------------------------------+

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.4.txt
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡


<Prev in Thread] Current Thread [Next in Thread>