spf-discuss
[Top] [All Lists]

Re: SPF is not usable as legal measure against spammers.

2004-07-14 09:57:45
CommunigatePro does all right from the box. It is easy to migrate from other
mailservers to it.



----- Original Message ----- 
From: "Paul Howarth" <paul(_at_)city-fan(_dot_)org>
To: <spf-discuss(_at_)v2(_dot_)listbox(_dot_)com>
Sent: Wednesday, July 14, 2004 12:50 PM
Subject: Re: [spf-discuss] SPF is not usable as legal measure against
spammers.


John Keown wrote:
That is correct but in order to relay through our server the other
domain
must pass our test as a closed secure mta and smtp authentication both
their
users and the mta.

The only hack is then one of the hacker getting access to the user's
email
address and password and spamming that way. But a good mta will restrict
the
number of messages per unit time from an individual user and thus make
it
impractable to spam.

The MTA should also ensure that the sender domain name being used is
allowed
to be used by the authenticated user. These are all fine things to do but
how
many MTAs current enforce such rules? I'm not aware of *any* MTA that can
easily do all of these things "out of the box" and if the number of ISPs
actually doing this right now is more than a fraction of one percent, I'd
be
amazed. It therefore follows that SPF *on its own* is not a guarantee that
the
purported sender authorized the mail.

Paul.

-------
Sender Policy Framework: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Send us money!  http://spf.pobox.com/donations.html
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com



<Prev in Thread] Current Thread [Next in Thread>