spf-discuss
[Top] [All Lists]

Re: SPF: Not just a clever idea

2004-06-07 10:08:31
"Stuart D. Gathman" <stuart(_at_)bmsi(_dot_)com> writes:

Once again, the 2822 functionality is useful - but does not belong in
the MTA.  The code bloat from the XML, the non-trivial cryptography, will be a
security nightmare.  Fortunately, that functionality does not have to be
in the MTA.  Since we already committed to DATA, the complete message has
already been transferred, and external tools can apply the 2822 check.
The external tools do not even have to be real time.

Is that strictly true? Surely even for 2822 post-DATA checks it is
better for the MTA to reject the mail rather than for later checks to
generate a bounce (or even send to /dev/null).