spf-discuss
[Top] [All Lists]

Re: Possible New Mechanism Prefix

2004-06-24 19:48:42
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

spf(_at_)kitterman(_dot_)com wrote:
|
|
| I have asked, but that doesn't really help the problem I'm concerned
about.
| All that would accomplish is changing ip4:204.127.202.0/24 to
| include:comcast.net.  The ISP can't "SPFize" my domain, since I don't host
| it there and we use different MTAs run by different companies depending on
| how we are connecting.
|
Right, your correct SPF record would be
"v=spf1 a mx ?include:comcast.net -all"

This says: If it is from a machine I directly control, it
is definitely me, if it is from a machine comcast says is OK
it is probably me, if it is from anywhere else it is a forgery, drop it.

? _is_ the "softpass" type you are asking about, we just call
it "neutral". You aren't supposed to drop neutral results, because
the policy of the domain sending the mail says they might be valid.


In practice, my bayesian filter says that _most_ neutral results
are associated with spam, but not all. (This hasn't shifted much since I
turned "guess" on either, but I don't have a lot of traffic there yet).

- --
Daniel Taylor
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFA25KK8/QSptFdBtURArY8AJ0QB/qdibXC8uateZKdPhy2vQiHmwCdGItA
IHm5TjH5kknEOFymmoxRJXE=
=eLSC
-----END PGP SIGNATURE-----