spf-discuss
[Top] [All Lists]

Re: Unified SPF Algorithm (was: moving on from MARID)

2004-10-01 01:29:27
I believe what you are saying is that the RCPT TO: should be evaluated
before any other checks. I don't have any specific statistics to support
this, but I have noticed in previous work that there was a very
significant
level of email addressed to non-existent or expired customers. The RCPT
TO:
should be evaluated first,

Rejecting based upon RCPT TO alone is a significant logical hole it allows
automated address harvesters to poll an MTA with random addresses so that
it can build up a list of valid ones.

Far better to validate upon receipt of all three, and reject with no notice
of what check failed.

d.



***************************************************************************
The information in this e-mail is confidential and for use by the addressee(s) 
only. If you are not the intended recipient (or responsible for delivery of the 
message to the intended recipient) please notify us immediately on 0141 306 
2050 and delete the message from your computer. You may not copy or forward it 
or use or disclose its contents to any other person. As Internet communications 
are capable of data corruption Student Loans Company Limited does not accept 
any  responsibility for changes made to this message after it was sent. For 
this reason it may be inappropriate to rely on advice or opinions contained in 
an e-mail without obtaining written confirmation of it. Neither Student Loans 
Company Limited or the sender accepts any liability or responsibility for 
viruses as it is your responsibility to scan attachments (if any). Opinions and 
views expressed in this e-mail are those o
 f the sender and may not reflect the opinions and views of The Student Loans 
Company Limit
 ed.

This footnote also confirms that this email message has been swept for the 
presence of computer viruses.

**************************************************************************