spf-discuss
[Top] [All Lists]

Re: ENVID to prevent forged bounces with SUBMITTER?

2004-06-05 15:34:34
The MTA at orig.com can now use the "Original-Envelope-ID:" to
determine whether the bounce is valid. Ideally, the ENVID would get
passed back on the DSN's RCPT command, but alas it does not. I
suppose if we are adding SUBMITTER to MAIL FROM, we could add ENVID
parameter to RCPT, like this:

EHLO third.com
MAIL FROM: <>
RCPT TO: <ann(_at_)orig(_dot_)com> ENVID=yf09+Cw

Why can't the DSN look like this:

EHLO third.com
MAIL FROM: <> ENVID=yf09+Cw
RCPT TO: <ann(_at_)orig(_dot_)com>

That would make for a very clean SES without munging the localpart.
In fact, I am not sure what ENVID is good for without it being
spit back in some manner.

-- 
              Stuart D. Gathman <stuart(_at_)bmsi(_dot_)com>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flamis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.