spf-discuss
[Top] [All Lists]

Re: SPF-compliant phishing?

2004-09-15 06:49:55
Hmm. Very interesting.
I should have recognized this before.

Well, it does fix Mr. Woodhouses objections, as this
mechanism would allow at least two of the forgeries he
presented to be caught, if not the lot. It is more
involved to setup however, and the additional administration
will likely prevent widespread use of the more complicated
mechanisms for a while.

Roger Moser wrote:
Daniel Taylor wrote:


SPF does not validate users.


The current syntax allows SPF to validate the local part on the envelope
sender. So it can validate users. For example:

mxout                   A       192.168.1.2
@                       TXT     "v=spf1 exists:%{l}.%{i}.spf.%{o} -all"
John.192.168.1.2        A       127.0.0.2
Mary.192.168.1.2        A       127.0.0.2

Roger


--
Daniel Taylor          VP Operations            Vocal Laboratories, Inc.
dtaylor(_at_)vocalabs(_dot_)com   http://www.vocalabs.com/        
(952)941-6580x203


<Prev in Thread] Current Thread [Next in Thread>