spf-discuss
[Top] [All Lists]

RE: Response to the Bellovin Critique of SPF

2004-01-25 14:41:46
Aredridel [aredridel(_at_)nbtsc(_dot_)org] wrote:
On Sat, Jan 24, 2004 at 10:52:22AM -0600, wayne wrote:
Phishing is going to be very hard to stop.  However, comparing the
envelope-from with the From: header goes a very long ways.

Actually, that's starting to be implemented. MS Outlook 2003 now
displays the From: field thus:

      From: service(_at_)paypal(_dot_)com on behalf of 
bad(_at_)spammer(_dot_)com

It's a step.  Still forgeable, but that's what SPF is for ;-)

Could you please tell us the "Return-Path:", "From:", and "Sender:" headers of 
that message?

I think Outlook 2003, as do Outlook 2000 and probably 2002, displays

  From: $SENDER on behalf of $FROM

I doubt that any version of Outlook that's currently available displays the 
envelope sender ("Return-Path:").

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.4.txt
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)���v¼����ߴ��1I�-�Fqx(_dot_)com