spf-discuss
[Top] [All Lists]

Re: Oh That

2004-01-25 13:22:49
David Saez wrote:
spf will stop all spam comming from hacked client computers. It will
require spammers to buy domains that they must spf-enable so mail could
be accepted from dls/cable hacked computers. This costs money and is
easy to detect.

Erm, no, not in most cases.

If a hacked system detects the email address and SMTP server of the system's user and uses that to spam from, the spam will look like a legitimate message to SPF.

If the hack imitates the user it will only be detected if it sends directly from the user's PC (ignoring the configured SMTP server) AND that IP falls outside the user's SPF-specified senders.

SPF will, however, be of use if the hack uses the spammer's domain name or a third-party one.

        Wechsler
--
This message protected by the SPF protocol - adopt it now!
Details: http://spfwiki.infinitepenguins.net/

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.4.txt
Wiki: 
http://spfwiki.infinitepenguins.net/pmwiki.php/SenderPermittedFrom/HomePage
To unsubscribe, change your address, or temporarily deactivate your subscription, please go to http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡


<Prev in Thread] Current Thread [Next in Thread>