spf-discuss
[Top] [All Lists]

Re: SPF extension

2004-02-04 18:09:57
On Wed, Feb 04, 2004 at 07:08:24PM -0600, wayne wrote:
| In 
<2A1D4C86842EE14CA9BC80474919782E0356EF9B(_at_)mou1wnexm02(_dot_)vcorp(_dot_)ad(_dot_)vrsn(_dot_)com>
 "Hallam-Baker, Phillip" <pbaker(_at_)verisign(_dot_)com> writes:
| 
| > Maybe we should look at the type of behavior you might want for S/MIME. One
| > reason you might deploy S/MIME would be to address the roaming issue. So you
| > would want to say something like 'all mail from these addresses comes from
| > either this set of IP addresses or has an S/MIME signature.'
| >
| >  v=spf1 mx smime -all
| 
| But this SPF spec is misleading because most SPF clients will actually
| see this as:  "v=spf1 mx ?all"
| 
| If you use a modifier, things are clearer.  If you say
| "v=spf1 mx -all smime=_smime.%{p}", then it is clear to everyone that
| the default will be -all if the special client doesn't recognize the
| smime extention.  Of, if you really want to return unknown in such
| case, you would specify "?all" instead of "-all".

If the client doesn't recognize smime, do you really want it to fail?

If the client does recognize smime, and the message is a forgery, do you
really want it to return neutral?

-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.9.5.txt
Wiki: http://spfwiki.infinitepenguins.net/pmwiki.php/SenderPermittedFrom/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡


<Prev in Thread] Current Thread [Next in Thread>