spf-discuss
[Top] [All Lists]

Re: A couple of thoughts

2004-02-15 11:03:30
In <200402151756(_dot_)I1FHUVEU094818(_at_)asarian-host(_dot_)net> Mark 
<admin(_at_)asarian-host(_dot_)net> writes:

On the other hand, RCPT TO: is guaranteed to always work (which, if you
think about it, kinda defeats the purpose of disallowing VRFY, as the same
info can be obtained through using RCPT TO:).

MAIL FROM:<>/RCPT TO:<test> is not guaranteed to always work.  Many
mailers say "ok" to every RCPT TO: command.  Some will delay the error
code for until a data command is issued (I think Yahoo does this),
others will simply accept and create a bounce message.

However, your point of being silly to disable the VRFY command when it
is so easy to simulate is on target.  There really isn't any reason to
disable it.  On the other hand, since it is so easy to simulate, there
really isn't any reason for people to use it.


-wayne