spf-discuss
[Top] [All Lists]

Re: getting 2822 protection as well as 2821 protection

2004-04-06 22:17:57
PHB has been proposing on the MXCOMP list that if 2821 does not match
2822, the MUA should put up a red flag.

I think this is a brilliant idea, because it gives receivers something
they can comprehend: if it's a mailing list message, they don't mind the
red flag, but if it's claiming to be from eBay, they should be
suspicious.

The only thing I can say is that I'd hope it is more informational than
yes-no in a good UI:

        From: joe(_at_)example(_dot_)org, transmitted by 
list(_at_)example(_dot_)com

instead of 

  From: (Red flag) joe(_at_)example(_dot_)org

I think this is a good, good practice (In fact, it codifies how I verify
emails already -- I read the from, if it looks bogus, I check the
headers, and glance at the Received: lines to see if there's something
valid in the chain or not.

Ari