spf-discuss
[Top] [All Lists]

Re: Possible SPF machine-domain loophole???

2004-02-24 10:41:21
On Tue, Feb 24, 2004 at 05:54:56PM +0100, Ernesto Baschny wrote:
I don't understand what you call "null envelope sender". The problem 
here is forging the HELO string (sending client name). Maybe it's not
your case, but I can tell you that spammers are using my domain in the
envelope HELO string. And even if this is just a string in the Received
headers, it's still enough for many people to think I am responsible for
the spam.

I get around 2-3 UBE-complaints each day

... from cluebaits who do not know how to read mail headers.

From what I read here, it sounds like this is actually the fundamental
problem which we are trying to solve. "I don't want my domain to be abused"
translates to "I don't want my domain appearing in Return-Path: or Received:
headers"

In which case there must be an easier way? Like a BCP which says don't
include HELO names in Received: headers?

Regards,

Brian.