spf-discuss
[Top] [All Lists]

RE: A hole in planned phishing-prevention?

2004-06-14 08:51:42
On Fri, 4 Jun 2004, Seth Goodman wrote:

That gets rid of the Sender parameter.  Sender is automatically validated
when we validate MAIL FROM: on the first hop.  OnBehalfOf is really the
From: header and that's a sticky question.  Does anyone outside the same
domain _really_ send mail in anyone else's behalf anymore, aside from
mailing lists?  I can honestly say that I have never sent mail in someone
else's behalf and have never received a non-list message sent in someone
else's behalf.  Someone will probably send me one now so that I can't make
that claim anymore :)

This message is an example, though it's me using my facilities at work to
send a message on behalf of me in a personal capacity. (My personal email
domain is hosted at work for testing purposes.) This kind of distinction
between a single user's multiple role addresses is very common.

-- 
Tony Finch  <dot(_at_)dotat(_dot_)at>  http://dotat.at/