On Tue, Aug 10, 2004 at 09:17:54AM -0500, Jonathan C. Detert wrote:
        This is all good, but I also need to know the following:
        - a log of each request that was failed, including the date,
          sender address, the purported 'mail from' header, and the 
          intended recipient.
Isn't this info logged already by the standard implementation? Can't you just 
grep it out of the postfix log? (i'm no postfix expert)
        - how to make postfix send an explanation back to the sender
          of why the email was rejected.
When mail is rejected, any conforming spf implementation will read out the spf 
records exp domain, and use that as the 550 error message. Usually, this 
message is then send back to the sender by the original mta.
        - ideally, I'd like to send a rejection reply to the sender
          and quarantine the email instead of rejecting it, so that
          I have a full copy of the email to examine in case of problems.
This is NOT ideal. Don't do this. If spf rejects, this most likely means the 
sender address is forged. You don't want to harras innocent bystanders with 
automated replies, now don't you??
Koen
-- 
K.F.J. Martens, Sonologic, http://www.sonologic.nl/
Networking, embedded systems, unix expertise, artificial intelligence.
Public PGP key: http://www.metro.cx/pubkey-gmc.asc
Wondering about the funny attachment your mail program
can't read? Visit http://www.openpgp.org/
-------
Sender Policy Framework: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
http://www.InboxEvent.com/?s=d --- Inbox Event Nov 17-19 in Atlanta features 
SPF and Sender ID.
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com
 pgpKIFHpYdIQr.pgp
pgpKIFHpYdIQr.pgp
Description: PGP signature