spf-discuss
[Top] [All Lists]

Re: [SPF Classic] Privacy and disclosure of 2821 MAIL FROM

2004-10-06 23:49:40
On Thu, Oct 07, 2004 at 01:32:30AM +0100,
 Jim Hill <spf-0408(_at_)mx(_dot_)rdns(_dot_)org> wrote 
 a message of 48 lines which said:

I'm not clear what you're getting at. What privacy expectations
do roaming users have in the context of spf?

It is widely accepted in the mobility world that recipients should not
be aware of the actual location of the sender.

Let's say Alice is at a conference. She uses the hotel's network to
send mail. She configures her MUA to tell "From:
alice(_at_)mycompany(_dot_)com". But, to be aceptable by SPF MTAs, the mail will
have an envelope from (2821 MAIL FROM) of "customer(_at_)thehotel(_dot_)com". It
is already visible in Return-Path and the Received headers but a
SPF-aware MUA will display it more prominently and therefore may cause
privacy concerns.