spf-discuss
[Top] [All Lists]

Re: Latest proposal re HELO checking: make HELO tests optional

2004-03-10 18:27:15
In <20040311021617(_dot_)A2461(_at_)slot(_dot_)hollandcasino(_dot_)net> Alex 
van den Bogaerdt <alex(_at_)ergens(_dot_)op(_dot_)het(_dot_)net> writes:

Are you by any chance doing dynamic RCPT validation _without_ making sure
the RHS is valid?

It is my understanding that Hector will check to make sure that the
RHS of the RCPT TO address is a customer that his system is willing to
forward to.  Since I highly doubt that he runs an open relay, I would
say that the number of domains that he will do dynamic RCPT TO
validation is very small and if any of those folks have problems with
it, they can stop paying him to forward email.


IMHO you need SPF...  Once you've validated the RHS, you can do call backs.

That is certianly much more valid if you are doing MAIL FROM call backs.

-wayne


<Prev in Thread] Current Thread [Next in Thread>