spf-discuss
[Top] [All Lists]

Re: Google's gmail.com checks spf records!

2004-09-08 11:27:13
On Wed, 8 Sep 2004, jpinkerton wrote:

Any script kiddie can write a script which will insert false Reply-To:
addresses in their spam, and *that* is what I thought we were sorting out?

SPF only authenticates RFC2821 headers (envelope).  Authenticating 
RFC2822 headers is what Unified SPF and Sender-ID are addressing
(not very well IMHO - I think Domain Keys has a better change for
RFC2822 authentication).

-- 
              Stuart D. Gathman <stuart(_at_)bmsi(_dot_)com>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flamis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.