spf-discuss
[Top] [All Lists]

Re: The demon problem, ancestor matching, and match_subdomains=yes

2004-03-21 20:03:40
On Friday March 19, mengwong(_at_)dumbo(_dot_)pobox(_dot_)com wrote:
On Fri, Mar 19, 2004 at 05:24:25PM -0500, Stuart D. Gathman wrote:
| Also, when SPF returns 'none', should I
| check smaller right hand sides?  E.g. check mx.aol.com, then aol.com 
| (which would pass).
| 

We've been thinking about this.  Some thinking is at:
http://spf.pobox.com/faq.html#demon

But maybe we want to allow ancestor search for a record with a
match_subdomains=yes modifier.

Would it make sense to take the following approach:

 If there is no SPF record for the domain, but there are MX records,
 choose an MX record with minimal priority and look for an SPF record
 at that domain.

I think this would do the right thing all the time, and makes it a lot
easier to manage SPF records.

NeilBrown