spf-discuss
[Top] [All Lists]

Re: Calling ISPs: does bandwidth matter to your bottom line?

2004-01-26 09:53:21
On Mon, 26 Jan 2004, Mark Shewmaker wrote:

: I misread:  When you mentioned "dropping the TCP connection" above I
: simply read right through that without comprehending what you actually
: said, somehow reading instead that you were again referring to the same
: sort of rejection-at-"." that I and everyone has been talking about,
: namely, returning a 5xx error.

OK, clarification made.  It's likely that I misinterpreted an earlier post
that referred to "dropping" a connection in relation to consuming all the
message at DATA time.

: 2.  You then claim that a check at DATA is more expensive, as the
:     entire data stream must be sent.
:
:     My question is "More expensive than what?":
:
:     o  More expensive than an envelope check?
:
:        Nope:  We've already done an envelope check, the message so far
:        passed it, and so we're now obliged to receive the entire data
:        stream anyway.

Yes, but the expense comes under the assumption that a body check is perhaps
the *only* SPF method provided by the potentially forgeable domain in their
TXT record.  If that's the case, then there is no envelope check at all, and
it is indeed more expensive to process that message's SPF authenticity.

This is where the whole concept about "allowing senders to be lazy" comes
from.  If SPF-authenticated senders are permitted (or worse yet, encouraged)
to do body-only checks, then the lightweight value of SPF is dead in the
water.  If using SPF, envelope checks should be mandatory, and body checks
optional as a [secondary] method of reassurance only.

(And, once you reach that point, why include body checks in SPF at all?
What would it buy you?)

-- 
-- Todd Vierling <tv(_at_)duh(_dot_)org> <tv(_at_)pobox(_dot_)com>

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.4.txt
Wiki: 
http://spfwiki.infinitepenguins.net/pmwiki.php/SenderPermittedFrom/HomePage
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡


<Prev in Thread] Current Thread [Next in Thread>