spf-discuss
[Top] [All Lists]

Re: Re: "extreme SPF" scenario for ISPs

2004-02-03 06:35:33


On 3 Feb 2004 at 4:28, Dan Boresjo wrote:

On Tuesday 03 February 2004 3:59 am, John Warren wrote:
You change the port on your MUA to use port 587 and authenticate. 
Simple, you don't need port 25 it the MTA your connecting to is not 
broken.

You are missing the point. A 'mail server' is whatever I say it is.

And SMTP-AUTH is only good for remote MTA's that I have an account with, it 
is 
not a general-purpose solution.

Only if you have an account on that MTA. If you don't then you go 
through your assigned MTA.

No No NO! Again you miss the point. I want my delivery to a THIRD PARTY, VIA 
STANDARD ESMTP STARTTLS ENCRYPTION to be PRIVATE.

I do NOT have or need any kind of 'account' on this server, and I DO NOT 
TRUST 
my ISP with the mail.

And with SPF your going to have the same problem. If your using your 
ISP domain name and they have a "-all" then if the system your trying 
to send the mail to checks it they will reject your message.  


Let's start with the US. After than we could always pressure the ISP to 
use a blacklist of foreign ISP that don't.

That will never work. You seem to think it is obvious what a valid 'mail 
server' is and what is not. This is naive.

No it's not my definition but the Internets, check out RFC 2476, as 
follows.

Message Submission Agent (MSA)

   A process which conforms to this specification, which acts as a
   submission server to accept messages from MUAs, and either delivers
   them or acts as an SMTP client to relay them to an MTA.

Message Transfer Agent (MTA)

   A process which conforms to [SMTP-MTA], which acts as an SMTP server
   to accept messages from an MSA or another MTA, and either delivers
   them or acts as an SMTP client to relay them to another MTA.

Message User Agent (MUA)

   A process which acts (usually on behalf of a user) to compose and
   submit new messages, and process delivered messages.  In the split-
   MUA model, POP or IMAP is used to access delivered messages.


Personally I think a 'valid mail server' is any IP address. Period.

And with that way of thinking your supporting the spammers and hackers. 
You in the minority on this one.

 
Fine, let them. Now we know what the address are so they will be easy 
to block.

They will keep setting up new ones, and they will sue anyone who gets in the 
way of their right to send spam.

Under what legal grounds? Even the CAN-SPAM act, as bad as it is, does 
not give them any room to take legal action. It supports the right to 
block spammers.


I support SPF but it's not a cure all. Unless several problems are 
corrected corporate users will never us it.

What are these problems?

Corporate road warriors that for some reason can't contact their 
company mail server to send mail. Now this problem has to be solved, 
and I think it can, before corporate users are going to support SPF.


Yes, spammers. I really don't care if they run mail server and if fact 
I would support them doing so. Make it easier for me to block them.

Your views are so extreme, I think you would be better off whitelisting.

You may think so but a lot of ISP are already doing this. 

One example, AOL. You can't send using port 25 on their network, well 
you can but it still get's routed through their outbound mail servers, 
and they are very likely to put in full port 25 blocks very soon. When 
they do this you will still be allowed to use port 587 and in fact are 
supporting the MSA port.


-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.5.txt
Wiki: http://spfwiki.infinitepenguins.net/pmwiki.php/SenderPermittedFrom/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡


----------------------------------------------------------------------
John Warren
+--------------------------------------------------------------------+
| Any and all use of my email address for bulk email without my      |
| expressed permission is prohibited. This means NO JUNK EMAIL, SPAM.|
| Support the anti-Spam amendment, Join at http://www.cauce.org/     |
+--------------------------------------------------------------------+

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.5.txt
Wiki: http://spfwiki.infinitepenguins.net/pmwiki.php/SenderPermittedFrom/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡