spf-discuss
[Top] [All Lists]

Re: first spf-enabled spam

2004-04-11 23:53:59
Hi !!

Looks like blueyonder is an ISP.  They need to be a bit more restrictive
with their record, listing only the approved outbound mail servers,
rather than the entire network including DSL nodes.

Blueyonder is one of the two or three cable ISPs in the UK. Every
subscriber gets a blueyonder email address, but it's fine for them
to send directly.

i don't feel that this is ok, spf enabling all their cable users means
that any zombie computer in this zone can start forging their emails,
it also allows any user to start using other's users email addresses, which is totally opposite to spf idea as there is no guarantee that
any email comming from this isp was really sent by the real owner.
In fact there is no reason to trust that emails comming from this
isp has not been forged, as opossite from isp's that only publish
spf records for hosts that use smtp auth to authenticate their users.

--
Best regards ...

A little inaccuracy sometimes saves tons of explanation.

----------------------------------------------------------------
   David Saez Padros                http://www.ols.es
   On-Line Services 2000 S.L.       e-mail  david(_at_)ols(_dot_)es
   Pintor Vayreda 1                 telf    +34 902 50 29 75
   08184 Palau-Solita i Plegamans   movil   +34 670 35 27 53
----------------------------------------------------------------