spf-discuss
[Top] [All Lists]

Re: No use of checking RFC2822 headers

2004-09-29 06:24:09
In <2998(_at_)rama(_dot_)pamho(_dot_)net> "Roger Moser" 
<Roger(_dot_)Moser(_at_)rama(_dot_)pamho(_dot_)net> writes:

Michel Py wrote:

This is yesterday's news. What you describe here has been the workhorse
of phishers for years.

If it is already known to you that Microsoft's Outlook does not display the
RFC 2822 mailbox address, then why the development of SPF Classic has been
                                    ^ has?
stopped and there are discussions about Sender-ID, PRA and other methods
that check the RFC 2822 mailbox addresses?

The development of SPF-classic has not stopped, fortunately.  As for
why the PRA?  Well, because when MS talks, people listen, even when
they say things that are as absurd as "The PRA protects what people
see" and "the PRA works correctly with most email currently being
sent".


First finish SPF Classic, then educate Microsoft, and only then talk about
Sender-ID, PRA etc.

Educating MS is may well be a harder problem than solving the phishing
problem.


-wayne