spf-discuss
[Top] [All Lists]

Re: softfail considered harmful

2004-02-18 16:51:49
On Wed, Feb 18, 2004 at 07:47:31AM -0500, Hector Santos wrote:
A True Positive can not be trusted 100%, where a True Negative has a 100%
trust value:

      0 < trust positive < trust negative = 100%

A example if a True Positive would be a SPF compliant spammer who said "wow!
maybe I can sneak in if I add a SPF record!"

Erm, I think there is a distinction between:
(1) trusting that this mail came from domain X, and
(2) trusting that this mail was not spam

SPF can help you with (1), but not with (2). If the spammer adds SPF records
to his domain, and sends you a mail, you can have high confidence that the
spammer does, indeed, own that domain. [Big deal - they just blew $3 on a
throwaway domain before sending you a spam]

So as far as I can see, the level of confidence you can have in either a
positive or negative answer from SPF is about the same.

Regards,

Brian.


<Prev in Thread] Current Thread [Next in Thread>