spf-discuss
[Top] [All Lists]

Re: Is SPF Authenication or Authorization?

2004-09-21 13:09:12
On Tue, 21 Sep 2004, Mark wrote:

I really disagree. When you check my SPF record, really the only thing you 
can determine, is whether the relay is authorized to send mail on behalf of 
my domain name. You cannot, as receiver, authenticate the "RFC2821.MailFrom" 
address with that information. For one, because SPF checks are done against 
the RHS of the domain, not the LHS (local part) of the address.

The SPF checks are done against both LHS and RHS of the address.  It is up
to the sender whether the LHS is actually used (via the exist mechanism, for
instance).

-- 
              Stuart D. Gathman <stuart(_at_)bmsi(_dot_)com>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flamis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.